API tokens a person makes for scripts and agents to act as them (#123)
The API took a session cookie, a proxy's word or the shared admin token, so a script or an agent working for one person had to sign in with their password and carry the cookie, or be given the admin token. Settings now makes named tokens, ipx_ and 256 random bits, sent as Authorization: Bearer. A token is its owner and no more. Only its SHA-256 is kept, in the new api_tokens table, with when it was made and last used; it is shown once and revoked from the same list. An unknown or revoked one gets a 401 rather than falling through to a cookie. Cloudflare Access still stands in front of the tunnel, so from outside a token needs an Access service token beside it; docs/sso.md says how. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -287,6 +287,29 @@ pub mod sessions {
|
||||
owned_by_user!();
|
||||
}
|
||||
|
||||
/// A token a script or agent sends as `Authorization: Bearer`, acting as the person who made
|
||||
/// it (#123). Kept as its SHA-256, so the table is no use to anyone who reads it.
|
||||
pub mod api_tokens {
|
||||
use sea_orm::entity::prelude::*;
|
||||
|
||||
#[derive(Clone, Debug, PartialEq, Eq, DeriveEntityModel)]
|
||||
#[sea_orm(table_name = "api_tokens")]
|
||||
pub struct Model {
|
||||
#[sea_orm(primary_key)]
|
||||
pub id: i64,
|
||||
pub user_id: i64,
|
||||
/// What its owner called it, to tell one from another when revoking.
|
||||
#[sea_orm(column_type = "Text")]
|
||||
pub name: String,
|
||||
#[sea_orm(unique, column_type = "Text")]
|
||||
pub hash: String,
|
||||
pub created: i64,
|
||||
pub last_used: Option<i64>,
|
||||
}
|
||||
|
||||
owned_by_user!();
|
||||
}
|
||||
|
||||
/// The catalogue: every feed configured, with its shared settings as `config::Feed` in JSON, so a
|
||||
/// new setting on a feed needs no new column. It was config.toml's `[feeds]` (issue #18).
|
||||
pub mod catalogue {
|
||||
|
||||
Reference in New Issue
Block a user