feat: P0 commercial readiness — password security, legal, account management
Backend changes for Phase A of v1.0 commercial launch: P0-3: Password Security - Remove hardcoded admin/123456 defaults from 34+ bootstrap scripts - Add PLATFORM_USERNAME/PLATFORM_PASSWORD env vars to config - Add PUT /api/v1/auth/change-password endpoint (requires old password) P0-1: User Agreement & Privacy Policy - Add agreed_terms/agreed_terms_version/agreed_terms_at to User model - New GET /api/v1/legal/privacy and GET /api/v1/legal/terms endpoints - New POST /api/v1/legal/agree endpoint to record consent - Register endpoint now validates agreed_terms must be True P0-6: Account Management - Add phone/status/is_email_verified to User model - Add DELETE /api/v1/auth/account for account deletion (with password confirmation) - Add PUT /api/v1/auth/phone for phone binding - Reject authentication for deleted accounts (status=deleted) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -159,8 +159,8 @@ def _via_requests() -> int:
|
||||
import requests
|
||||
|
||||
base = os.getenv("PLATFORM_BASE_URL", "http://127.0.0.1:8037").rstrip("/")
|
||||
user = os.getenv("PLATFORM_USERNAME", "admin")
|
||||
pwd = os.getenv("PLATFORM_PASSWORD", "123456")
|
||||
user = os.getenv("PLATFORM_USERNAME")
|
||||
pwd = os.getenv("PLATFORM_PASSWORD")
|
||||
wf = build_complex_workflow()
|
||||
_validate_local(wf)
|
||||
|
||||
@@ -250,8 +250,8 @@ def _via_testclient() -> int:
|
||||
lr = c.post(
|
||||
"/api/v1/auth/login",
|
||||
data={
|
||||
"username": os.getenv("PLATFORM_USERNAME", "admin"),
|
||||
"password": os.getenv("PLATFORM_PASSWORD", "123456"),
|
||||
"username": os.getenv("PLATFORM_USERNAME"),
|
||||
"password": os.getenv("PLATFORM_PASSWORD"),
|
||||
},
|
||||
headers={"Content-Type": "application/x-www-form-urlencoded"},
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user