Files
nvcurve/pyproject.toml
T
ARIA bbd692ea2e feat: multi-user authentication (dual mode)
Add optional login protection for the web UI/API, intended for shared
machines (e.g. AI servers). Dual mode: with no users configured the API
and web UI are open (as before); once at least one user exists, every
/api/* and /ws/* endpoint requires a valid session.

- bcrypt password hashing: passwords stored as $2b$ hashes in
  /etc/nvcurve/users.json (0600, root-owned); plaintext never persisted.
- 24-hour sessions: HttpOnly cookie for browsers, Authorization: Bearer
  token for CLI/scripts; in-memory, invalidated on server restart.
- Multi-user: multiple named accounts (no shared-password mode).
- New CLI: nvcurve user add|list|remove|set-password (root for mutating
  ops; password always prompted, never a CLI argument).
- New endpoints: GET /api/ping (public), /api/auth/status|login|logout|users.
- Web UI: sign-in screen when auth is enabled; status bar shows the
  signed-in user with sign-out; expired sessions (401) re-show sign-in.
- Brute-force lockout: 10 failed logins/IP within 5 min -> 15 min lockout.
- New dependency: bcrypt.

Also: LSP config (pyrightconfig.json) pointing at the project .venv, and
small error-handling cleanups in daemon.py/server.py.
2026-09-02 15:21:35 +02:00

34 lines
662 B
TOML

[build-system]
requires = ["hatchling"]
build-backend = "hatchling.build"
[project]
name = "nvcurve"
version = "0.5.1"
description = "Linux GPU V/F curve editor for NVIDIA GPUs"
requires-python = ">=3.12"
dependencies = [
"fastapi>=0.115",
"uvicorn[standard]>=0.30",
"nvidia-ml-py>=12.0",
"pydantic>=2.0",
"httpx>=0.27",
"bcrypt>=4.0",
]
[project.scripts]
nvcurve = "nvcurve.cli:main"
[tool.hatch.build.targets.wheel]
packages = ["nvcurve"]
[tool.hatch.build.targets.wheel.force-include]
"frontend/dist" = "nvcurve/frontend/dist"
[tool.hatch.build.targets.sdist]
include = [
"/nvcurve",
"/frontend/dist",
"/README.md",
]