Per-user auth via Nextcloud Login Flow v2, Tailwind UI rewrite

- auth.py/auth_routes.py: Login Flow v2 (verified against real NC
  source/docs) - no OAuth2 client registration needed, backend polls
  server-side so no CORS issues. Sessions are hashed-token cookies;
  NC app passwords encrypted at rest (Fernet). Every /api/* route
  guarded by a blueprint-wide before_request, not per-route decorators,
  so future routes are protected by default.
- receipts/groups scoped per owner_nc_user_id; cross-user access 404s.
- nc_client/cospend_client take (username, app_password) per call
  instead of one shared global credential - each user's uploads/shares/
  bills now happen as themselves.
- Frontend: LoginGate component drives the login flow (open NC login
  in a new tab, poll our backend, done).
- Merged the old separate review step into the split screen, redesigned
  with Tailwind (was unstyled/broken), default-excluded-per-item
  splitting with one-click "include everyone" fixed, DD.MM.YYYY date
  field, receipt-icon branding.
- Dropped LLM bounding-box highlighting - unreliable on real receipts,
  plain photo upload instead.
- Only mention who a bill is split with in its title when there's more
  than one bill off the same receipt to disambiguate.
This commit is contained in:
2026-08-30 16:02:29 +02:00
parent d97aac0e17
commit 1b38396a2c
31 changed files with 1653 additions and 746 deletions
+18 -5
View File
@@ -1,12 +1,13 @@
# Copy to .env and fill in. Never commit .env.
# --- Nextcloud ---
# Server address only - each user logs in themselves via Nextcloud Login
# Flow v2 (see /auth/login/start); there's no shared NC_USERNAME/APP_PASSWORD
# any more.
NC_BASE_URL=https://cloud.dominik-roth.eu
NC_USERNAME=dodox
# Settings -> Security -> "Devices & Sessions" -> create app password
NC_APP_PASSWORD=
# Folder (relative to the user's files root) receipt images get uploaded to.
# Created automatically on first upload if missing (each path segment).
# Folder (relative to each user's own files root) receipt images get
# uploaded to. Created automatically on first upload if missing (each path
# segment).
NC_UPLOAD_FOLDER=Documents/Cospend/Assets
# --- Cospend ---
@@ -29,3 +30,15 @@ LLM_MODEL=
# --- Flask ---
FLASK_SECRET_KEY=dev-change-me
DATABASE_PATH=instance/wgbill.sqlite3
# --- Auth ---
# Generate with: python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
# Encrypts stored Nextcloud app passwords at rest. Required - the app
# refuses to store/read a token without it. Keep this secret; losing it
# means every logged-in user has to log in again.
TOKEN_ENCRYPTION_KEY=
# Idle session lifetime in days (sliding - refreshed on each use).
SESSION_TTL_DAYS=30
# Cookies need Secure (HTTPS-only) for any real deployment. Only set to
# false for plain-http localhost dev.
SESSION_COOKIE_SECURE=true