Per-user auth via Nextcloud Login Flow v2, Tailwind UI rewrite
- auth.py/auth_routes.py: Login Flow v2 (verified against real NC source/docs) - no OAuth2 client registration needed, backend polls server-side so no CORS issues. Sessions are hashed-token cookies; NC app passwords encrypted at rest (Fernet). Every /api/* route guarded by a blueprint-wide before_request, not per-route decorators, so future routes are protected by default. - receipts/groups scoped per owner_nc_user_id; cross-user access 404s. - nc_client/cospend_client take (username, app_password) per call instead of one shared global credential - each user's uploads/shares/ bills now happen as themselves. - Frontend: LoginGate component drives the login flow (open NC login in a new tab, poll our backend, done). - Merged the old separate review step into the split screen, redesigned with Tailwind (was unstyled/broken), default-excluded-per-item splitting with one-click "include everyone" fixed, DD.MM.YYYY date field, receipt-icon branding. - Dropped LLM bounding-box highlighting - unreliable on real receipts, plain photo upload instead. - Only mention who a bill is split with in its title when there's more than one bill off the same receipt to disambiguate.
This commit is contained in:
+16
-3
@@ -17,10 +17,10 @@ class Config:
|
||||
|
||||
CORS_ORIGIN = os.environ.get("CORS_ORIGIN", "http://localhost:5173")
|
||||
|
||||
# Server address only - who's calling is now per logged-in user (see
|
||||
# auth.py), not a single shared NC_USERNAME/NC_APP_PASSWORD.
|
||||
NC_BASE_URL = os.environ.get("NC_BASE_URL", "").rstrip("/")
|
||||
NC_USERNAME = os.environ.get("NC_USERNAME", "")
|
||||
NC_APP_PASSWORD = os.environ.get("NC_APP_PASSWORD", "")
|
||||
NC_UPLOAD_FOLDER = os.environ.get("NC_UPLOAD_FOLDER", "wgBill").strip("/")
|
||||
NC_UPLOAD_FOLDER = os.environ.get("NC_UPLOAD_FOLDER", "Documents/Cospend/Assets").strip("/")
|
||||
|
||||
# Optional - pre-selects a project in the UI; the app lists all of the
|
||||
# user's Cospend projects via the API either way, so this isn't required.
|
||||
@@ -29,3 +29,16 @@ class Config:
|
||||
LLM_BASE_URL = os.environ.get("LLM_BASE_URL", "").rstrip("/")
|
||||
LLM_API_KEY = os.environ.get("LLM_API_KEY", "")
|
||||
LLM_MODEL = os.environ.get("LLM_MODEL", "")
|
||||
|
||||
# Fernet key (Fernet.generate_key()) used to encrypt stored NC app
|
||||
# passwords at rest. Required in production; a request-time error is
|
||||
# raised if missing so this can't be silently skipped.
|
||||
TOKEN_ENCRYPTION_KEY = os.environ.get("TOKEN_ENCRYPTION_KEY", "")
|
||||
|
||||
SESSION_COOKIE_NAME = "wgbill_session"
|
||||
# Sessions are sliding - refreshed on use, so an active user never gets
|
||||
# logged out; an idle one expires after this many days.
|
||||
SESSION_TTL_DAYS = int(os.environ.get("SESSION_TTL_DAYS", "30"))
|
||||
# Cookies need Secure (HTTPS-only) in any real deployment; only disable
|
||||
# for plain-http local dev.
|
||||
SESSION_COOKIE_SECURE = os.environ.get("SESSION_COOKIE_SECURE", "true").lower() == "true"
|
||||
|
||||
Reference in New Issue
Block a user