Fix LOW findings from 2026-09-24 maintenance review
- Frontend on nginx-unprivileged (non-root, container port 8080) - Replace unmaintained passlib with bcrypt 5.0.0 (hash-compatible) - Pass DOCS_ENABLED through to the backend container - Raise db mem_limit to 768m for MySQL 8.4 Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
1 parent
f74bc1a1ff
commit
eed5a8fb12
6 files changed
+30
-12
No files matched your search
+11
-4
@@ -3,21 +3,28 @@ from typing import Any
|
||||
|
||||
import jwt
|
||||
from jwt import PyJWTError
|
||||
from passlib.context import CryptContext
|
||||
import bcrypt
|
||||
|
||||
from app.config import get_settings
|
||||
|
||||
settings = get_settings()
|
||||
|
||||
pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto")
|
||||
|
||||
def _encode(plain: str) -> bytes:
|
||||
# bcrypt only uses the first 72 bytes; passlib truncated silently, so do the
|
||||
# same to keep existing hashes verifiable (bcrypt>=5 raises instead).
|
||||
return plain.encode("utf-8")[:72]
|
||||
|
||||
|
||||
def hash_password(plain: str) -> str:
|
||||
return pwd_context.hash(plain)
|
||||
return bcrypt.hashpw(_encode(plain), bcrypt.gensalt(rounds=12)).decode("ascii")
|
||||
|
||||
|
||||
def verify_password(plain: str, hashed: str) -> bool:
|
||||
return pwd_context.verify(plain, hashed)
|
||||
try:
|
||||
return bcrypt.checkpw(_encode(plain), hashed.encode("ascii"))
|
||||
except ValueError: # malformed hash
|
||||
return False
|
||||
|
||||
|
||||
def create_access_token(data: dict[str, Any]) -> str:
|
||||
|
||||
Reference in new issue
Block a user