Security closeout: settings public allowlist, audit.view gating, test-user guard
Settings exposure (review medium): GET /api/settings and /api/settings/<key> now return the full table only to an authenticated principal. Unauthenticated callers (kiosk dashboards, print pages, login screen, setup router) get just a public allowlist - categories branding + map plus a named set (site_base_url, facility_name, printer_hostname_template, contact_email_domain, servicenow_enabled, setup_complete). A non-public single-key GET returns 404 so existence is not confirmed. Secrets stay masked in both cases. Closes the unauthenticated enumeration of smtp_host / employee_db_host / zabbix_url / servicenow URLs. Allowlist mirrors the keys siteSettings.js + mapConfig.js + setupState.js read before login. audit.view (review low): the three audit-read routes (list, entity-history, stats) were jwt_required only despite a defined-but-unwired audit.view permission; now gated by it (seeded to admin), so a role-less member or unscoped PAT can no longer read the cross-user audit trail. flask seed test-user (review low): refuses outside DEBUG/TESTING - it creates the well-known admin/admin123; production sites use `flask seed admin`. Tests: unauthenticated allowlist + authed-full-masked + private-key-404, and member-403 / admin-200 on audit routes. 336 authz tests pass; naming green. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -5,6 +5,7 @@ from flask_jwt_extended import jwt_required
|
||||
|
||||
from shopdb.core.models import AuditLog
|
||||
from shopdb.utils.responses import success_response
|
||||
from shopdb.utils.authz import require_permission
|
||||
|
||||
auditlogs_bp = Blueprint('auditlogs', __name__)
|
||||
|
||||
@@ -51,6 +52,7 @@ def _resolve_full_names(ssos):
|
||||
|
||||
@auditlogs_bp.route('', methods=['GET'])
|
||||
@jwt_required()
|
||||
@require_permission('audit.view')
|
||||
def list_auditlogs():
|
||||
"""
|
||||
List audit logs with filtering and pagination.
|
||||
@@ -134,6 +136,7 @@ def list_auditlogs():
|
||||
|
||||
@auditlogs_bp.route('/entity/<entitytype>/<int:entityid>', methods=['GET'])
|
||||
@jwt_required()
|
||||
@require_permission('audit.view')
|
||||
def get_entity_history(entitytype: str, entityid: int):
|
||||
"""Get audit history for a specific entity."""
|
||||
logs = AuditLog.query.filter_by(
|
||||
@@ -146,6 +149,7 @@ def get_entity_history(entitytype: str, entityid: int):
|
||||
|
||||
@auditlogs_bp.route('/stats', methods=['GET'])
|
||||
@jwt_required()
|
||||
@require_permission('audit.view')
|
||||
def get_stats():
|
||||
"""Get audit log statistics."""
|
||||
from sqlalchemy import func
|
||||
|
||||
Reference in New Issue
Block a user