Feat: Implement basic web authentication and UI
This commit introduces the foundation for web-based authentication and user interface. It includes: - **Session Management**: Securely handling user sessions using cryptographically generated tokens, cookies with appropriate security flags, and server-side storage. - **Login/Logout Functionality**: Endpoints for users to log in with their credentials and log out, clearing their session. - **User Interface**: Basic templates for the login page, a list of cases, and a detailed view of a single case, allowing users to navigate and view their data. - **Authorization**: An `AuthenticatedWebUser` extractor to ensure only logged-in users can access protected web routes. - **Configuration**: Added a `cookie_secure` option to the configuration to control the `Secure` flag on session cookies, useful for local development. - **Dependencies**: Added necessary dependencies for password hashing, time handling, and TOML file manipulation. - **Helper Binary**: Included a `hash-password` binary to simplify generating bcrypt hashes for user passwords.
This commit is contained in:
@@ -53,6 +53,10 @@ pub struct Config {
|
||||
pub llm_model: String,
|
||||
pub llm_temperature: f32,
|
||||
pub session_timeout_hours: u32,
|
||||
/// Whether to set the `Secure` flag on the session cookie. Default `true`.
|
||||
/// Set `COOKIE_SECURE=false` only for plain-HTTP local development —
|
||||
/// browsers refuse `Secure` cookies on non-HTTPS origins.
|
||||
pub cookie_secure: bool,
|
||||
}
|
||||
|
||||
impl Config {
|
||||
@@ -82,6 +86,7 @@ impl Config {
|
||||
llm_model: optional_env("LLM_MODEL", ""),
|
||||
llm_temperature: optional_env_parsed("LLM_TEMPERATURE", 0.0),
|
||||
session_timeout_hours: optional_env_parsed("SESSION_TIMEOUT_HOURS", 8),
|
||||
cookie_secure: optional_env_parsed("COOKIE_SECURE", true),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user