diff options
| author | omnom62 <omnom62@outlook.com> | 2026-08-12 14:38:00 +1000 |
|---|---|---|
| committer | John Estabrook <jestabro@vyos.io> | 2026-08-26 13:33:34 -0500 |
| commit | d62e57071f2afb83879f576f6a3af5ecaa21023b (patch) | |
| tree | c46867432e1cb2e9321899590adde02506343b46 /src/services/api | |
| parent | a4a52a0975ce4de70c43fa6cab1e09f55567dc35 (diff) | |
| download | vyos-1x-d62e57071f2afb83879f576f6a3af5ecaa21023b.tar.gz vyos-1x-d62e57071f2afb83879f576f6a3af5ecaa21023b.zip | |
http-api: T8989: address review comments
- Make ApiModel.key optional to allow Bearer/X-API-Key/mTLS auth
without requiring a dummy key field in the request body
- Add thread safety to REST token secret initialization
- Cast rest_token_exp and rest_secret_len to int on load
- Use defensive dict.get() for authentication config access
Diffstat (limited to 'src/services/api')
| -rw-r--r-- | src/services/api/rest/libs/token_auth.py | 11 | ||||
| -rw-r--r-- | src/services/api/rest/models.py | 3 |
2 files changed, 10 insertions, 4 deletions
diff --git a/src/services/api/rest/libs/token_auth.py b/src/services/api/rest/libs/token_auth.py index 08a6155a1..87464eb0f 100644 --- a/src/services/api/rest/libs/token_auth.py +++ b/src/services/api/rest/libs/token_auth.py @@ -14,25 +14,30 @@ # along with this library. If not, see <http://www.gnu.org/licenses/>. import datetime +import threading from secrets import token_hex import jwt from ...session import SessionState +_secret_lock = threading.Lock() + def init_secret(): state = SessionState() if state.rest_secret is not None: return - length = state.rest_secret_len or 32 - state.rest_secret = token_hex(length) + length = int(state.rest_secret_len or 32) + with _secret_lock: + if state.rest_secret is None: + state.rest_secret = token_hex(length) def generate_token(key_id: str) -> dict: state = SessionState() init_secret() - exp_interval = state.rest_token_exp or 3600 + exp_interval = int(state.rest_token_exp or 3600) expiration = datetime.datetime.now(tz=datetime.timezone.utc) + datetime.timedelta( seconds=exp_interval ) diff --git a/src/services/api/rest/models.py b/src/services/api/rest/models.py index abe7e7726..8321ad2e3 100644 --- a/src/services/api/rest/models.py +++ b/src/services/api/rest/models.py @@ -20,6 +20,7 @@ import json from html import escape from enum import Enum from typing import List +from typing import Optional from typing import Union from typing import Dict from typing import Self @@ -52,7 +53,7 @@ def success(data): class ApiModel(BaseModel): - key: StrictStr + key: Optional[StrictStr] = None class BasePathModel(BaseModel): |
