feat(auth): single-admin password login (signed cookie) — gate tuning + Sources catalog, keep chat and document viewer public
This commit is contained in:
@@ -31,6 +31,13 @@ MOCK_PORT = int(os.environ.get("E2E_MOCK_PORT", "8901"))
|
||||
APP_URL = f"http://127.0.0.1:{APP_PORT}"
|
||||
USE_REAL_LLM = os.environ.get("E2E_REAL_LLM") == "1"
|
||||
|
||||
# Phase 16: the app under test boots with single-admin auth configured
|
||||
# (fail-loud otherwise). Known E2E values — the shared form-login helper
|
||||
# (tests/e2e/auth_helpers.py) uses ADMIN_PASSWORD; the secret is fixed so
|
||||
# session cookies stay valid across a session-scoped app restart.
|
||||
ADMIN_PASSWORD = "e2e-admin-password"
|
||||
SESSION_SECRET = "e2e-session-secret-0123456789abcdef0123456789abcdef"
|
||||
|
||||
|
||||
def _wait_http(url: str, timeout: float = 40.0) -> None:
|
||||
deadline = time.monotonic() + timeout
|
||||
@@ -89,6 +96,9 @@ def app_server(mock_llm: int) -> Iterator[str]:
|
||||
# `embed` model's 0.41–0.84 cosine range, PLAN A8).
|
||||
env["BOR_RELEVANCE_THRESHOLD"] = "0.30"
|
||||
env.setdefault("BOR_DATABASE_URL", "postgresql+psycopg://reese:reese@localhost:5432/brain_of_reese")
|
||||
# Phase 16: admin auth must be set or create_app() refuses to boot.
|
||||
env["BOR_ADMIN_PASSWORD"] = ADMIN_PASSWORD
|
||||
env["BOR_SESSION_SECRET"] = SESSION_SECRET
|
||||
proc = subprocess.Popen(
|
||||
[sys.executable, "-m", "uvicorn", "app.main:app",
|
||||
"--host", "127.0.0.1", "--port", str(APP_PORT), "--log-level", "warning"],
|
||||
|
||||
Reference in New Issue
Block a user