From d62e57071f2afb83879f576f6a3af5ecaa21023b Mon Sep 17 00:00:00 2001 From: omnom62 Date: Wed, 12 Aug 2026 14:38:00 +1000 Subject: http-api: T8989: address review comments - Make ApiModel.key optional to allow Bearer/X-API-Key/mTLS auth without requiring a dummy key field in the request body - Add thread safety to REST token secret initialization - Cast rest_token_exp and rest_secret_len to int on load - Use defensive dict.get() for authentication config access --- src/services/api/rest/libs/token_auth.py | 11 ++++++++--- src/services/api/rest/models.py | 3 ++- 2 files changed, 10 insertions(+), 4 deletions(-) (limited to 'src/services/api') diff --git a/src/services/api/rest/libs/token_auth.py b/src/services/api/rest/libs/token_auth.py index 08a6155a1..87464eb0f 100644 --- a/src/services/api/rest/libs/token_auth.py +++ b/src/services/api/rest/libs/token_auth.py @@ -14,25 +14,30 @@ # along with this library. If not, see . import datetime +import threading from secrets import token_hex import jwt from ...session import SessionState +_secret_lock = threading.Lock() + def init_secret(): state = SessionState() if state.rest_secret is not None: return - length = state.rest_secret_len or 32 - state.rest_secret = token_hex(length) + length = int(state.rest_secret_len or 32) + with _secret_lock: + if state.rest_secret is None: + state.rest_secret = token_hex(length) def generate_token(key_id: str) -> dict: state = SessionState() init_secret() - exp_interval = state.rest_token_exp or 3600 + exp_interval = int(state.rest_token_exp or 3600) expiration = datetime.datetime.now(tz=datetime.timezone.utc) + datetime.timedelta( seconds=exp_interval ) diff --git a/src/services/api/rest/models.py b/src/services/api/rest/models.py index abe7e7726..8321ad2e3 100644 --- a/src/services/api/rest/models.py +++ b/src/services/api/rest/models.py @@ -20,6 +20,7 @@ import json from html import escape from enum import Enum from typing import List +from typing import Optional from typing import Union from typing import Dict from typing import Self @@ -52,7 +53,7 @@ def success(data): class ApiModel(BaseModel): - key: StrictStr + key: Optional[StrictStr] = None class BasePathModel(BaseModel): -- cgit v1.2.3