Backend: a GreetingToken model stores only a SHA-256 hash of a j621r_…
key (shown once at creation) plus label, prefix, created/last-used. A
dedicated GreetingTokenAuthentication understands the usual
'Authorization: Token …' header but is registered only on RandomItemView
(alongside the normal token auth), so a greeting token authenticates
/api/random/ and is rejected with 401 everywhere else — exactly the scope
shell greetings need. Endpoints: GET/POST /api/auth/greeting-tokens/ and
DELETE /api/auth/greeting-tokens/{id}/ (own tokens only; the list never
returns keys or hashes).
Frontend: /tokens page (Account → Shell tokens card, command palette entry)
lists tokens with label, prefix, created/last-used and revoke (shared
confirm dialog). Creating one shows the key with Copy and 'Copy for fish'
buttons plus a pointer to extras/fish_greeting.
Tests: apps/accounts/tests/test_greeting_tokens.py — 9 tests covering
create-once semantics and hashing, hidden keys in listings, the scope
guarantee (random 200 with a signed URL; 401 on files, storage, me, tags
cloud, delete and the token list itself), unknown/revoked keys, cross-user
revocation, last-used tracking and label limits.
Verified live: created a token, rolled /random (signed URL), got 401 from
four other endpoints, saw the list omit secrets, revoked it (204) and the
same key then 401'd on /random. Full suite: 39 tests green.
20 lines
894 B
Fish
20 lines
894 B
Fish
# Copy to ~/.config/j621Greeting/config.fish and adjust. All of these can also
|
|
# be universal variables, e.g. `set -Ux J621_BASE https://j621.example.ts.net`.
|
|
|
|
# API origin (no trailing slash needed).
|
|
set -g J621_BASE https://j621.rainbow-herring.ts.net
|
|
|
|
# Web origin used in the printed link. Only needed when the SPA is served
|
|
# from a different host than the API (split deployment).
|
|
# set -g J621_WEB https://j621-frontend.rainbow-herring.ts.net
|
|
|
|
# API token. Optional: gives you signed image URLs and access to items that
|
|
# are hidden from guests. Use a scoped greeting token (Account -> Shell
|
|
# tokens, or /tokens in the app): those only work with /api/random/, so they
|
|
# are safe to keep in this file. The full API token works too, but grants
|
|
# everything.
|
|
# set -g J621_TOKEN paste-your-token-here
|
|
|
|
# fastfetch config name used for the greeting logo.
|
|
# set -g J621_FASTFETCH_CONFIG jake
|