Fix all 7 launch blockers from security/QA review

SEC-16: Add frontend ports mapping (80:80) to docker-compose.yml
UI-01:  Add routes for Welcome, SettingsIntegrations, MealPlan in App.jsx
SEC-01: Remove traceback leak from auth error responses
SEC-02: Fix require_admin to use is_admin column (was undefined ADMIN_USERNAME)
SEC-03: Add API_TOKEN auth for MCP connector -> backend communication
SEC-04: OAuth state now uses signed JWT tokens (was raw user UUID)
OS-01:  First registered user gets admin immediately during registration

10 files changed, 97 insertions(+), 25 deletions(-)
This commit is contained in:
Claude 2026-06-16 01:50:09 +00:00
parent 50eae17c34
commit 69320e1e82
10 changed files with 97 additions and 25 deletions

View file

@ -12,6 +12,7 @@ from datetime import date
from mcp.server.fastmcp import FastMCP
FITNESS_API_URL = os.getenv("FITNESS_API_URL", "http://backend:8000")
API_TOKEN = os.getenv("API_TOKEN", "")
mcp = FastMCP("Diligence Fitness", port=3001)
@ -21,8 +22,12 @@ _client: httpx.AsyncClient | None = None
async def api(method: str, path: str, **kwargs) -> dict:
global _client
if _client is None:
_client = httpx.AsyncClient(base_url=FITNESS_API_URL, timeout=30)
# TODO: add service account API key auth header
headers = {}
if API_TOKEN:
headers["Authorization"] = f"Bearer {API_TOKEN}"
_client = httpx.AsyncClient(
base_url=FITNESS_API_URL, timeout=30, headers=headers
)
resp = await getattr(_client, method)(f"/api{path}", **kwargs)
resp.raise_for_status()
return resp.json()