security: M-2 HttpOnly-Cookie + M-4 TrustedHost-Warning + M-5 TOTP-Lockout + M-7 zentraler get_client_ip()

M-2: Refresh-Token als HttpOnly SameSite=Strict Cookie
- auth.py: _set_refresh_cookie/_delete_refresh_cookie Helpers
- Alle Auth-Endpoints (login, totp/login, refresh, logout) nutzen Cookie
- schemas/auth.py: refresh_token in Request/Response optional
- AuthContext.tsx: kein refresh_token in localStorage
- api/client.ts: credentials:include, kein Token-Body beim Refresh

M-4: TrustedHostMiddleware Warning in Production
- main.py: Startup-Warning wenn is_production + kein ALLOWED_HOSTS

M-5: TOTP-Fehlversuche Redis-Lockout
- auth.py: _check/_record/_clear_totp_lockout; 5 Versuche → 15 min Sperre

M-7: Zentraler get_client_ip()-Helper
- core/dependencies.py: get_client_ip() mit X-Real-IP → X-Forwarded-For → client.host
- hours_payouts.py, absences.py, busylight.py: request.client.host ersetzt

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-05-26 11:25:24 +02:00
co-authored by Claude Sonnet 4.6
parent 9887a2a623
commit 721d33a04c
11 changed files with 183 additions and 39 deletions
+10 -4
View File
@@ -17,19 +17,25 @@ export function AuthProvider({ children }: { children: ReactNode }) {
const navigate = useNavigate()
async function login(email: string, password: string) {
const data = await api.post<{ access_token: string; refresh_token: string }>(
// refresh_token kommt nicht mehr im Body nur noch als HttpOnly-Cookie
const data = await api.post<{ access_token: string; refresh_token?: string | null }>(
'/auth/login',
{ email, password },
)
localStorage.setItem('access_token', data.access_token)
localStorage.setItem('refresh_token', data.refresh_token)
// refresh_token NICHT mehr in localStorage speichern (M-2: HttpOnly-Cookie)
setToken(data.access_token)
navigate('/dashboard')
}
function logout() {
async function logout() {
// Cookie wird vom Backend gelöscht; kein refresh_token aus localStorage nötig
try {
await api.post('/auth/logout', {})
} catch {
// Logout-Fehler ignorieren lokal trotzdem ausloggen
}
localStorage.removeItem('access_token')
localStorage.removeItem('refresh_token')
setToken(null)
navigate('/login')
}