fix: remove dead auth_refresh code, fix logout storage, align bootstrap TTL, add hash rehash, tighten CSP

- Remove duplicate dead code in daemon/handlers/auth.py (auth_refresh)
- Fix logout reading refresh token from localStorage instead of sessionStorage
- Align bootstrap auth config access_token_ttl (900 -> 300) with hardened default
- Add password hash rehash check on successful login (needs_rehash was unused)
- Remove 'unsafe-inline' from CSP style-src (all styles are applied via JS DOM API)
This commit is contained in:
2026-07-24 03:06:31 +00:00
parent a365059976
commit edaf16a433
5 changed files with 9 additions and 29 deletions
+1 -1
View File
@@ -45,7 +45,7 @@ def main() -> None:
config = {
"jwt": {
"access_token_ttl": 900,
"access_token_ttl": 300,
"refresh_token_ttl": 604800,
"algorithm": "HS256",
},