diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/config.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/config.py | 18 |
1 files changed, 18 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/config.py b/packages/meshbay-hub/src/meshbay_hub/config.py index 48d5a6e..39fdc52 100644 --- a/packages/meshbay-hub/src/meshbay_hub/config.py +++ b/packages/meshbay-hub/src/meshbay_hub/config.py @@ -65,11 +65,25 @@ class JWTConfig: class CaptchaConfig: site_key: str = "" secret_key: str = "" + # Hostnames a solved captcha may have come from, checked against the one + # `siteverify` reports. Empty means "do not check", which is right while + # the reCAPTCHA key does its own origin check โ it is then already done. + # + # Set this when that check is turned off in the reCAPTCHA console, which is + # what the desktop client needs: its page is served from `app://meshbay`, + # so the hostname Google sees is not the hub's and never can be. See + # docs/captcha.md ยง6. + allowed_hosts: list[str] = field(default_factory=list) @property def enabled(self) -> bool: return bool(self.site_key and self.secret_key) + @property + def host_check(self) -> frozenset[str] | None: + """The set to hand `verify_captcha`, or None for "do not check".""" + return frozenset(self.allowed_hosts) if self.allowed_hosts else None + @dataclass class HubConfig: @@ -106,6 +120,8 @@ def load_config(path: Path | None = None) -> HubConfig: if cap := raw.get("captcha", {}): cfg.captcha.site_key = cap.get("site_key", cfg.captcha.site_key) cfg.captcha.secret_key = cap.get("secret_key", cfg.captcha.secret_key) + if hosts := cap.get("allowed_hosts"): + cfg.captcha.allowed_hosts = [str(h).strip() for h in hosts if str(h).strip()] break # Env var overrides @@ -125,5 +141,7 @@ def load_config(path: Path | None = None) -> HubConfig: cfg.captcha.site_key = captcha_site if captcha_secret := os.environ.get("MESHBAY_CAPTCHA_SECRET_KEY"): cfg.captcha.secret_key = captcha_secret + if captcha_hosts := os.environ.get("MESHBAY_CAPTCHA_ALLOWED_HOSTS"): + cfg.captcha.allowed_hosts = [h.strip() for h in captcha_hosts.split(",") if h.strip()] return cfg |