Sites now enforce their license offline (client-services KI-006): the
cloud is needed to renew a license, not to run it. Each heartbeat carries
license_token = base64url(payload).base64url(signature), payload
{v:1, site_id, active, locked, lock_reason, expires_at, issued_at}, signed
with LICENSE_SIGNING_KEY (base64 raw Ed25519 private key, cloud .env). The
matching public key is built into the site code, so a stored token can't be
edited and a clock can't be set before issued_at unnoticed.
Additive field only (old sites ignore it). Without the key the field is
null and a warning is logged. Pins cryptography==46.0.4 (was transitive).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
34 lines
1.1 KiB
Python
34 lines
1.1 KiB
Python
import os
|
|
from pathlib import Path
|
|
from pydantic_settings import BaseSettings
|
|
|
|
_HERE = Path(__file__).parent
|
|
|
|
if os.name == "nt":
|
|
_DB_DIR = Path(os.environ.get("LOCALAPPDATA", Path.home() / "AppData" / "Local")) / "xenia_cloud"
|
|
_DB_DIR.mkdir(parents=True, exist_ok=True)
|
|
_DEFAULT_DB = _DB_DIR / "cloud.db"
|
|
else:
|
|
_DEFAULT_DB = _HERE / "cloud.db"
|
|
|
|
|
|
class Settings(BaseSettings):
|
|
SECRET_KEY: str = "change-me-generate-a-long-random-string"
|
|
DATABASE_URL: str = f"sqlite:///{_DEFAULT_DB.as_posix()}"
|
|
ACCESS_TOKEN_EXPIRE_MINUTES: int = 60
|
|
ADMIN_USERNAME: str = "sysadmin"
|
|
ADMIN_PASSWORD: str = "changeme"
|
|
LATEST_VERSION: str = "0.0.0"
|
|
# Ed25519 private key (base64, raw 32 bytes) that signs sites' license tokens.
|
|
# Generated once; the matching public key is built into client-services
|
|
# (local_backend/services/license.py). Keep secret, back up.
|
|
LICENSE_SIGNING_KEY: str = ""
|
|
# Manager JWT (separate secret from admin JWT)
|
|
MANAGER_JWT_SECRET: str = "change-me-manager-secret"
|
|
MANAGER_JWT_EXPIRE_HOURS: int = 72
|
|
|
|
model_config = {"env_file": str(_HERE / ".env")}
|
|
|
|
|
|
settings = Settings()
|