feat(web): optional web login and API tokens, off by default (stacked on #674) (#683)

Optional web login, off by default: a device that sets no password behaves
exactly as before. Set under General > Security; then every page and API
route needs a session login or an API token (Authorization: Bearer).
Loopback, the Wi-Fi setup flow in AP mode, static files, captive-portal
probes and a reduced /api/v3/health stay open. Secrets live in the web_auth
section of config_secrets.json and no API returns them.
scripts/reset_web_password.py turns login off. Stacked on #674.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-30 09:09:40 -04:00
committed by GitHub
co-authored by Claude Opus 5.5
parent ba38a83c2c
commit e3c85cece6
23 changed files with 2310 additions and 26 deletions
+50
View File
@@ -1,4 +1,54 @@
[
[
"/api/v3/auth/disable",
"api_v3.disable_web_login",
[
"OPTIONS",
"POST"
]
],
[
"/api/v3/auth/password",
"api_v3.set_web_password",
[
"OPTIONS",
"POST"
]
],
[
"/api/v3/auth/status",
"api_v3.get_web_auth_status",
[
"GET",
"HEAD",
"OPTIONS"
]
],
[
"/api/v3/auth/tokens",
"api_v3.create_api_token",
[
"OPTIONS",
"POST"
]
],
[
"/api/v3/auth/tokens",
"api_v3.list_api_tokens",
[
"GET",
"HEAD",
"OPTIONS"
]
],
[
"/api/v3/auth/tokens/<token_id>",
"api_v3.revoke_api_token",
[
"DELETE",
"OPTIONS"
]
],
[
"/api/v3/backup/<path:filename>",
"api_v3.backup_delete",