fix(security): python-jose CVE-2024-33663 durch pyjwt ersetzt, Deps gepinnt

- security.py/dependencies.py/auth.py: jose -> pyjwt (unmaintained,
  Algorithm-Confusion-CVE). API-kompatibel (jwt.encode/decode gleich).
- requirements.txt: alle Versionen gepinnt (waren >=, jetzt == anhand
  aktueller 137-Installation) fuer reproduzierbare Deploys.
- nginx.conf: /docs + /openapi.json nur noch aus LAN erreichbar (waren
  oeffentlich, API-Struktur-Leak).

fail2ban auf 137+164 installiert (sshd + nginx-badbots + timemaster-auth
Jails), Configs nicht im Repo (Server-only, /etc/fail2ban/).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LTxkZEUdfgMxZvHPiZJ8bV
This commit is contained in:
2026-08-05 19:10:28 +02:00
co-authored by Claude Sonnet 5
parent 7c24887ec1
commit 2046f6475b
6 changed files with 79 additions and 33 deletions
+29 -29
View File
@@ -1,29 +1,29 @@
fastapi>=0.110.0
uvicorn[standard]>=0.27.0
sqlalchemy[asyncio]>=2.0.0
asyncpg>=0.29.0
alembic>=1.13.0
pydantic[email]>=2.6.0
pydantic-settings>=2.2.0
python-jose[cryptography]>=3.3.0
bcrypt>=4.0.0
openpyxl>=3.1.0
ldap3>=2.9.0
cryptography>=42.0.0
python-multipart>=0.0.9
slowapi>=0.1.9
limits>=3.6.0
redis>=5.0.0
resend>=0.7.0
python-dateutil>=2.9.0
pyotp>=2.9.0
httpx>=0.27.0
icalendar>=5.0.0
pytest>=8.0.0
pytest-asyncio>=0.23.0
pytest-httpx>=0.30.0
aiosqlite>=0.20.0
weasyprint>=61.0
typer>=0.12.0
rich>=13.7.0
apscheduler>=3.10.0
fastapi==0.135.2
uvicorn[standard]==0.42.0
sqlalchemy[asyncio]==2.0.48
asyncpg==0.31.0
alembic==1.18.4
pydantic[email]==2.12.5
pydantic-settings==2.13.1
pyjwt[crypto]==2.10.1
bcrypt==5.0.0
openpyxl==3.1.5
ldap3==2.9.1
cryptography==46.0.6
python-multipart==0.0.22
slowapi==0.1.9
limits==5.8.0
redis==7.4.0
resend==2.26.0
python-dateutil==2.9.0.post0
pyotp==2.9.0
httpx==0.28.1
icalendar==7.0.3
pytest==9.0.2
pytest-asyncio==1.3.0
pytest-httpx==0.36.0
aiosqlite==0.22.1
weasyprint==68.1
typer==0.25.1
rich==15.0.0
apscheduler==3.11.2