mirror of
https://github.com/hansjone/netx.git
synced 2026-10-10 22:03:22 +08:00
feat(auth): add local login, audit, API keys, and system admin UI
Gate netx Web/API/WebCRT with JWT and per-user API tokens, bootstrap an admin with forced password change, and expose users/audit/API-key management under a System section. MCP can reuse data/auth/mcp_token without extra env for local labs. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
14f14d34bd
commit
6d4cd741ef
35 changed files with 2699 additions and 21 deletions
|
|
@ -29,6 +29,25 @@ def api_base_url() -> str:
|
|||
def api_headers() -> dict[str, str]:
|
||||
h = {"accept": "application/json"}
|
||||
tok = (os.getenv("NETX_API_TOKEN") or os.getenv("OCLAW_NETX_API_TOKEN") or "").strip()
|
||||
if not tok:
|
||||
# Lab default written by netx API bootstrap: data/auth/mcp_token
|
||||
candidates = [
|
||||
os.getenv("NETX_MCP_TOKEN_FILE", "").strip(),
|
||||
"data/auth/mcp_token",
|
||||
os.path.join(os.path.dirname(__file__), "..", "..", "..", "data", "auth", "mcp_token"),
|
||||
]
|
||||
for raw in candidates:
|
||||
if not raw:
|
||||
continue
|
||||
path = os.path.abspath(raw)
|
||||
try:
|
||||
if os.path.isfile(path):
|
||||
with open(path, encoding="utf-8") as fh:
|
||||
tok = fh.read().strip()
|
||||
if tok:
|
||||
break
|
||||
except Exception:
|
||||
continue
|
||||
if tok:
|
||||
h["authorization"] = f"Bearer {tok}"
|
||||
return h
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue