summaryrefslogtreecommitdiff
path: root/src/services/api
diff options
context:
space:
mode:
authoromnom62 <omnom62@outlook.com>2026-08-12 14:38:00 +1000
committerJohn Estabrook <jestabro@vyos.io>2026-08-26 13:33:34 -0500
commitd62e57071f2afb83879f576f6a3af5ecaa21023b (patch)
treec46867432e1cb2e9321899590adde02506343b46 /src/services/api
parenta4a52a0975ce4de70c43fa6cab1e09f55567dc35 (diff)
downloadvyos-1x-d62e57071f2afb83879f576f6a3af5ecaa21023b.tar.gz
vyos-1x-d62e57071f2afb83879f576f6a3af5ecaa21023b.zip
http-api: T8989: address review comments
- Make ApiModel.key optional to allow Bearer/X-API-Key/mTLS auth without requiring a dummy key field in the request body - Add thread safety to REST token secret initialization - Cast rest_token_exp and rest_secret_len to int on load - Use defensive dict.get() for authentication config access
Diffstat (limited to 'src/services/api')
-rw-r--r--src/services/api/rest/libs/token_auth.py11
-rw-r--r--src/services/api/rest/models.py3
2 files changed, 10 insertions, 4 deletions
diff --git a/src/services/api/rest/libs/token_auth.py b/src/services/api/rest/libs/token_auth.py
index 08a6155a1..87464eb0f 100644
--- a/src/services/api/rest/libs/token_auth.py
+++ b/src/services/api/rest/libs/token_auth.py
@@ -14,25 +14,30 @@
# along with this library. If not, see <http://www.gnu.org/licenses/>.
import datetime
+import threading
from secrets import token_hex
import jwt
from ...session import SessionState
+_secret_lock = threading.Lock()
+
def init_secret():
state = SessionState()
if state.rest_secret is not None:
return
- length = state.rest_secret_len or 32
- state.rest_secret = token_hex(length)
+ length = int(state.rest_secret_len or 32)
+ with _secret_lock:
+ if state.rest_secret is None:
+ state.rest_secret = token_hex(length)
def generate_token(key_id: str) -> dict:
state = SessionState()
init_secret()
- exp_interval = state.rest_token_exp or 3600
+ exp_interval = int(state.rest_token_exp or 3600)
expiration = datetime.datetime.now(tz=datetime.timezone.utc) + datetime.timedelta(
seconds=exp_interval
)
diff --git a/src/services/api/rest/models.py b/src/services/api/rest/models.py
index abe7e7726..8321ad2e3 100644
--- a/src/services/api/rest/models.py
+++ b/src/services/api/rest/models.py
@@ -20,6 +20,7 @@ import json
from html import escape
from enum import Enum
from typing import List
+from typing import Optional
from typing import Union
from typing import Dict
from typing import Self
@@ -52,7 +53,7 @@ def success(data):
class ApiModel(BaseModel):
- key: StrictStr
+ key: Optional[StrictStr] = None
class BasePathModel(BaseModel):