feat(web): optional web login and API tokens, off by default (stacked on #674) (#683)

Optional web login, off by default: a device that sets no password behaves
exactly as before. Set under General > Security; then every page and API
route needs a session login or an API token (Authorization: Bearer).
Loopback, the Wi-Fi setup flow in AP mode, static files, captive-portal
probes and a reduced /api/v3/health stay open. Secrets live in the web_auth
section of config_secrets.json and no API returns them.
scripts/reset_web_password.py turns login off. Stacked on #674.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-30 09:09:40 -04:00
committed by GitHub
co-authored by Claude Opus 5.5
parent ba38a83c2c
commit e3c85cece6
23 changed files with 2310 additions and 26 deletions
+24 -2
View File
@@ -475,7 +475,25 @@ def _load_general_partial():
auto_update_status = None
return render_template('v3/partials/general.html',
main_config=main_config,
auto_update_status=auto_update_status)
auto_update_status=auto_update_status,
web_login=_web_login_state())
def _web_login_state():
"""What the General tab's Security section shows; None hides it.
None when the app has no login store (a bare test app), so the section
only appears where it can work. Never includes a hash.
"""
from web_interface import auth as web_auth
store = web_auth.get_store()
if store is None:
return None
return {
'enabled': store.is_enabled(),
'tokens': store.list_tokens(),
'min_length': web_auth.MIN_PASSWORD_LENGTH,
}
def _load_display_partial():
"""Load display settings partial"""
@@ -592,7 +610,11 @@ def _load_raw_json_partial():
"""Load raw JSON editor partial"""
if pages_v3.config_manager:
main_config_data = pages_v3.config_manager.get_raw_file_content('main')
secrets_config_data = pages_v3.config_manager.get_raw_file_content('secrets')
# The web login section (password and token hashes) is managed in
# General > Security, never in this editor; its save keeps it.
from web_interface.auth import strip_auth_section
secrets_config_data = strip_auth_section(
pages_v3.config_manager.get_raw_file_content('secrets'))
main_config_json = json.dumps(main_config_data, indent=4)
secrets_config_json = json.dumps(secrets_config_data, indent=4)