Add optional login protection for the web UI/API, intended for shared machines (e.g. AI servers). Dual mode: with no users configured the API and web UI are open (as before); once at least one user exists, every /api/* and /ws/* endpoint requires a valid session. - bcrypt password hashing: passwords stored as $2b$ hashes in /etc/nvcurve/users.json (0600, root-owned); plaintext never persisted. - 24-hour sessions: HttpOnly cookie for browsers, Authorization: Bearer token for CLI/scripts; in-memory, invalidated on server restart. - Multi-user: multiple named accounts (no shared-password mode). - New CLI: nvcurve user add|list|remove|set-password (root for mutating ops; password always prompted, never a CLI argument). - New endpoints: GET /api/ping (public), /api/auth/status|login|logout|users. - Web UI: sign-in screen when auth is enabled; status bar shows the signed-in user with sign-out; expired sessions (401) re-show sign-in. - Brute-force lockout: 10 failed logins/IP within 5 min -> 15 min lockout. - New dependency: bcrypt. Also: LSP config (pyrightconfig.json) pointing at the project .venv, and small error-handling cleanups in daemon.py/server.py.
34 lines
662 B
TOML
34 lines
662 B
TOML
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[project]
|
|
name = "nvcurve"
|
|
version = "0.5.1"
|
|
description = "Linux GPU V/F curve editor for NVIDIA GPUs"
|
|
requires-python = ">=3.12"
|
|
dependencies = [
|
|
"fastapi>=0.115",
|
|
"uvicorn[standard]>=0.30",
|
|
"nvidia-ml-py>=12.0",
|
|
"pydantic>=2.0",
|
|
"httpx>=0.27",
|
|
"bcrypt>=4.0",
|
|
]
|
|
|
|
[project.scripts]
|
|
nvcurve = "nvcurve.cli:main"
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["nvcurve"]
|
|
|
|
[tool.hatch.build.targets.wheel.force-include]
|
|
"frontend/dist" = "nvcurve/frontend/dist"
|
|
|
|
[tool.hatch.build.targets.sdist]
|
|
include = [
|
|
"/nvcurve",
|
|
"/frontend/dist",
|
|
"/README.md",
|
|
]
|