feat: multi-user authentication (dual mode)
Add optional login protection for the web UI/API, intended for shared machines (e.g. AI servers). Dual mode: with no users configured the API and web UI are open (as before); once at least one user exists, every /api/* and /ws/* endpoint requires a valid session. - bcrypt password hashing: passwords stored as $2b$ hashes in /etc/nvcurve/users.json (0600, root-owned); plaintext never persisted. - 24-hour sessions: HttpOnly cookie for browsers, Authorization: Bearer token for CLI/scripts; in-memory, invalidated on server restart. - Multi-user: multiple named accounts (no shared-password mode). - New CLI: nvcurve user add|list|remove|set-password (root for mutating ops; password always prompted, never a CLI argument). - New endpoints: GET /api/ping (public), /api/auth/status|login|logout|users. - Web UI: sign-in screen when auth is enabled; status bar shows the signed-in user with sign-out; expired sessions (401) re-show sign-in. - Brute-force lockout: 10 failed logins/IP within 5 min -> 15 min lockout. - New dependency: bcrypt. Also: LSP config (pyrightconfig.json) pointing at the project .venv, and small error-handling cleanups in daemon.py/server.py.
This commit is contained in:
1 parent
af23a10f25
commit
bbd692ea2e
16 files changed
+2085
-483
No files matched your search
@@ -53,6 +53,18 @@ nvcurve # Launch web UI at http://localhost:8042
|
||||
nvcurve read # Quick curve read from CLI
|
||||
```
|
||||
|
||||
## Authentication (Multi-User)
|
||||
|
||||
The server runs **open by default**. On a shared machine (e.g. an AI server), add users to require a login — the web UI then shows a sign-in screen and every API/WebSocket call is protected. Passwords are stored as **bcrypt** hashes; sessions last **24 hours**.
|
||||
|
||||
```bash
|
||||
sudo nvcurve user add alice # add a user (prompts for password)
|
||||
nvcurve user list # list users
|
||||
sudo nvcurve user remove alice # remove a user
|
||||
```
|
||||
|
||||
Adding the first user enables authentication immediately; removing the last user disables it. See the [Usage Guide](docs/Usage-Guide.md#authentication-multi-user) for details.
|
||||
|
||||
## Systemd Service
|
||||
|
||||
Install the daemon for automatic profile loading on boot and optional web server auto-start:
|
||||
@@ -131,7 +143,7 @@ The daemon reads settings from `/etc/nvcurve/config.json`:
|
||||
```
|
||||
|
||||
| Setting | Description |
|
||||
|---|---|
|
||||
| --- | --- |
|
||||
| `host` | Web server bind address (`0.0.0.0` for network access) |
|
||||
| `port` | Web server port (default `8042`) |
|
||||
| `auto_serve` | Auto-start web server on boot |
|
||||
|
||||
Reference in new issue
Block a user