Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 11 additions & 8 deletions backend/.env.example
Original file line number Diff line number Diff line change
Expand Up @@ -64,19 +64,15 @@ CACHE_REDIS_POOL_SIZE=10
# ===================================
# Rate Limiting Configuration
# ===================================
# Provided by crudauth (Redis-backed). Limits are resolved per request from the
# user's tier and path, falling back to the defaults below.
RATE_LIMITER_ENABLED=true
# Options: memcached, redis
# redis (default) or memory; memory counters are per process
RATE_LIMITER_BACKEND=redis
RATE_LIMITER_FAIL_OPEN=true
DEFAULT_RATE_LIMIT_LIMIT=100
DEFAULT_RATE_LIMIT_PERIOD=60

# Rate Limiter Memcached settings (when using RATE_LIMITER_BACKEND=memcached)
RATE_LIMITER_MEMCACHED_HOST=localhost
RATE_LIMITER_MEMCACHED_PORT=11211
RATE_LIMITER_MEMCACHED_POOL_SIZE=10

# Rate Limiter Redis settings (when using RATE_LIMITER_BACKEND=redis)
# Rate Limiter Redis settings
# Uses DB 1 by default to separate from cache (which uses DB 0)
# For Docker Compose: use 'redis' (the service name)
# For local development without Docker: use 'localhost'
Expand Down Expand Up @@ -166,6 +162,13 @@ CSRF_ENABLED=true
# IP for login lockout. 0 = direct (socket peer); set 1 behind a single nginx/Caddy.
TRUSTED_PROXY_HOPS=0

# Password policy (crudauth applies this to every password-writing path)
PASSWORD_MIN_LENGTH=8
PASSWORD_REQUIRE_UPPERCASE=true
PASSWORD_REQUIRE_LOWERCASE=true
PASSWORD_REQUIRE_DIGIT=true
PASSWORD_REQUIRE_SPECIAL=true

# ===================================
# Admin Interface (SQLAdmin)
# ===================================
Expand Down
2 changes: 1 addition & 1 deletion backend/pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ dependencies = [
"aiosqlite>=0.21.0",
"alembic>=1.16.4",
"asyncpg>=0.30.0",
"crudauth[all]>=0.6.0,<0.7.0",
"crudauth[all]>=0.7.0,<0.8.0",
"faker>=37.1.0",
"fastapi[standard]>=0.115.8",
"fastcrud>=0.21.0",
Expand Down
12 changes: 5 additions & 7 deletions backend/src/infrastructure/app_factory.py
Original file line number Diff line number Diff line change
Expand Up @@ -29,8 +29,7 @@
from .database.initialize import close_database
from .database.session import create_tables
from .middleware import ClientCacheMiddleware, SecurityHeadersMiddleware
from .rate_limit.initialize import close_rate_limiter, initialize_rate_limiter
from .rate_limit.middleware import RateLimiterMiddleware
from .redis import cache_redis_client, rate_limiter_redis_client

logger = logging.getLogger(__name__)

Expand Down Expand Up @@ -65,8 +64,10 @@ async def lifespan(app: FastAPI) -> AsyncGenerator[None, None]:
teardown.push_async_callback(close_cache)

if isinstance(settings, RateLimiterSettings) and settings.RATE_LIMITER_ENABLED:
await initialize_rate_limiter()
teardown.push_async_callback(close_rate_limiter)
teardown.push_async_callback(rate_limiter_redis_client.aclose)

if not (isinstance(settings, CacheSettings) and settings.CACHE_ENABLED and settings.CACHE_BACKEND == "redis"):
teardown.push_async_callback(cache_redis_client.aclose)

teardown.push_async_callback(auth.shutdown)
await auth.initialize()
Expand Down Expand Up @@ -270,9 +271,6 @@ def create_application(

application.include_router(router)

if isinstance(settings, RateLimiterSettings) and settings.RATE_LIMITER_ENABLED:
application.add_middleware(RateLimiterMiddleware)

if isinstance(settings, CacheSettings) and settings.CACHE_ENABLED and hasattr(settings, "CLIENT_CACHE_ENABLED"):
if settings.CLIENT_CACHE_ENABLED:
client_cache_max_age = getattr(settings, "CLIENT_CACHE_MAX_AGE", 60)
Expand Down
46 changes: 0 additions & 46 deletions backend/src/infrastructure/auth/oauth.py

This file was deleted.

13 changes: 13 additions & 0 deletions backend/src/infrastructure/auth/password_policy.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
"""The password policy every password-writing path enforces, built from settings."""

from crudauth import PasswordPolicy

from ..config.settings import settings

password_policy = PasswordPolicy(
min_length=settings.PASSWORD_MIN_LENGTH,
require_uppercase=settings.PASSWORD_REQUIRE_UPPERCASE,
require_lowercase=settings.PASSWORD_REQUIRE_LOWERCASE,
require_digit=settings.PASSWORD_REQUIRE_DIGIT,
require_special=settings.PASSWORD_REQUIRE_SPECIAL,
)
Loading
Loading