feat(aincrad)!: separate read-only token vs full one - #575
Merged
Merged
Conversation
The API is now authenticated by two token hashes instead of one:
API_TOKEN_HASH_FULL, which may do anything, and API_TOKEN_HASH_READONLY,
which may only run the actions in READONLY_ACTIONS (currently `init`).
A read-only token used for anything else gets a 403 saying so.
The check itself moves to aincrad/auth.py and gains three things: a
constant-time comparison, support for a Django password hash (salted
PBKDF2) as an alternative to a bare SHA-256 digest, and acceptance of the
token in an `Authorization: Bearer` header. Existing SHA-256 hashes and
body tokens keep working, so only the new variable has to be deployed.
`./manage.py mkapitoken {full,readonly}` generates a random token and
prints the hash to configure it with.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JTXqG5HKnMgGZF5ebYzkXC
Accepting a Django password hash too was a choice nobody needed to make; the tokens are random strings, so SHA-256 is what they get. Drops the mkapitoken command along with it, since generating a random string belongs on a local machine rather than on the server. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JTXqG5HKnMgGZF5ebYzkXC
vEnhance
force-pushed
the
claude/aincrad-api-auth-4ih4yb
branch
2 times, most recently
from
September 29, 2026 17:46
5d999a2 to
d3b84e8
Compare
Owner
Author
|
yeah sure why not |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
also move the token into the header rather than in the POST body