mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-11 08:27:41 +00:00
All auth.json mutation methods now acquire _interprocess_auth_lock (flock-based) + _config_lock with reload-before-save, matching the pattern already used by create_user / create_user_oidc / set_oidc_user_admin. This prevents stale-write clobbers when an OIDC callback races a concurrent set_privileges, delete_user, rename_user, set_admin, change_password, or TOTP mutation from another uvicorn worker. Also: - Normalize setup() username (strip + lower) to match every other user-creation path, preventing "Alice" vs "alice" lockout. - Normalize in _create_user_locked() as defense-in-depth. - Remove dead _setup_lock — its serialisation was subsumed by _interprocess_auth_lock + _config_lock. - Move pre-lock validation inside the critical section for change_password, totp_generate_secret, and totp_confirm_enable. - Re-read backup codes from disk inside the lock in totp_verify() to prevent dual-consumption across workers. Co-Authored-By: antigravity <agy@antigravity> |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| atomic_io.py | ||
| auth.py | ||
| constants.py | ||
| database.py | ||
| exceptions.py | ||
| log_safety.py | ||
| middleware.py | ||
| models.py | ||
| oidc.py | ||
| platform_compat.py | ||
| session_manager.py | ||