Per-user auth via Nextcloud Login Flow v2, Tailwind UI rewrite
- auth.py/auth_routes.py: Login Flow v2 (verified against real NC source/docs) - no OAuth2 client registration needed, backend polls server-side so no CORS issues. Sessions are hashed-token cookies; NC app passwords encrypted at rest (Fernet). Every /api/* route guarded by a blueprint-wide before_request, not per-route decorators, so future routes are protected by default. - receipts/groups scoped per owner_nc_user_id; cross-user access 404s. - nc_client/cospend_client take (username, app_password) per call instead of one shared global credential - each user's uploads/shares/ bills now happen as themselves. - Frontend: LoginGate component drives the login flow (open NC login in a new tab, poll our backend, done). - Merged the old separate review step into the split screen, redesigned with Tailwind (was unstyled/broken), default-excluded-per-item splitting with one-click "include everyone" fixed, DD.MM.YYYY date field, receipt-icon branding. - Dropped LLM bounding-box highlighting - unreliable on real receipts, plain photo upload instead. - Only mention who a bill is split with in its title when there's more than one bill off the same receipt to disambiguate.
This commit is contained in:
+11
-2
@@ -15,13 +15,22 @@ def create_app() -> Flask:
|
||||
os.makedirs(Config.UPLOAD_DIR, exist_ok=True)
|
||||
|
||||
# Frontend runs on a different origin (vite dev server) during
|
||||
# development; lock this down to that origin in production.
|
||||
CORS(app, resources={r"/api/*": {"origins": Config.CORS_ORIGIN}})
|
||||
# development; lock this down to that origin in production. Auth now
|
||||
# relies on a session cookie, so credentials must be allowed - and with
|
||||
# supports_credentials, the origin allowlist can't be "*", it has to be
|
||||
# this one explicit origin (flask-cors enforces that).
|
||||
CORS(
|
||||
app,
|
||||
resources={r"/api/*": {"origins": Config.CORS_ORIGIN}, r"/auth/*": {"origins": Config.CORS_ORIGIN}},
|
||||
supports_credentials=True,
|
||||
)
|
||||
|
||||
init_db(Config.DATABASE_PATH)
|
||||
|
||||
from .auth_routes import bp as auth_bp
|
||||
from .routes import bp as api_bp
|
||||
|
||||
app.register_blueprint(api_bp, url_prefix="/api")
|
||||
app.register_blueprint(auth_bp, url_prefix="/auth")
|
||||
|
||||
return app
|
||||
|
||||
Reference in New Issue
Block a user