From de4a787bf2f843a5a2f9805b897876aacdc203e7 Mon Sep 17 00:00:00 2001 From: Noloquideus Date: Sun, 28 Jun 2026 14:12:24 +0300 Subject: [PATCH] fix: harden users startup and hashing --- src/infrastructure/config/settings.py | 2 ++ src/infrastructure/security/hash.py | 2 -- src/main.py | 13 +++++++++---- 3 files changed, 11 insertions(+), 6 deletions(-) diff --git a/src/infrastructure/config/settings.py b/src/infrastructure/config/settings.py index a1ceaa7..6f2e7eb 100644 --- a/src/infrastructure/config/settings.py +++ b/src/infrastructure/config/settings.py @@ -65,6 +65,8 @@ class Settings(BaseSettings): CSRF_COOKIE_PATH: str = '/' CSRF_COOKIE_DOMAIN: str | None = None + CORS_ALLOW_ORIGIN_REGEX: str = r'https?://([a-z0-9-]+\.)*elcsa\.ru(:\d+)?$' + DOCS_USERNAME: str = 'admin' DOCS_PASSWORD: str = 'admin' diff --git a/src/infrastructure/security/hash.py b/src/infrastructure/security/hash.py index 94d92b8..a321532 100644 --- a/src/infrastructure/security/hash.py +++ b/src/infrastructure/security/hash.py @@ -9,9 +9,7 @@ class HashService(IHashService): async def hash(self, value: str) -> str: hashed_value = bcrypt.hashpw(value.encode(), bcrypt.gensalt()) - self._logger.info(f'Hash value {hashed_value.decode()}') return hashed_value.decode() async def verify(self, hashed_value: str, plain_value: str) -> bool: - self._logger.info(f'Hash value {hashed_value[:10]}') return bcrypt.checkpw(plain_value.encode(), hashed_value.encode()) \ No newline at end of file diff --git a/src/main.py b/src/main.py index 6cf14ed..77a6a91 100644 --- a/src/main.py +++ b/src/main.py @@ -66,9 +66,14 @@ async def lifespan(app: FastAPI) -> AsyncGenerator[None, None]: app.state.jwt_key_store = jwt_store app.state.jwt_keys_scheduler = jwt_scheduler - yield - await app.state.redis.aclose() - logger.info(f'Users service instance ended with id {instance_id}') + try: + yield + finally: + sched = getattr(app.state,'jwt_keys_scheduler',None) + if sched: + sched.shutdown(wait=False) + await app.state.redis.aclose() + logger.info(f'Users service instance ended with id {instance_id}') app: FastAPI = FastAPI( @@ -107,7 +112,7 @@ app.add_middleware( app.add_middleware( CORSMiddleware, allow_origins=[], - allow_origin_regex='.*', + allow_origin_regex=settings.CORS_ALLOW_ORIGIN_REGEX, allow_credentials=True, allow_methods=['*'], allow_headers=['*'],