security: harden production configuration and routes
Run Tests on Branches / Detect Changes (push) Successful in 12s
Run Tests on Branches / Frontend Tests (push) Successful in 2m12s
Run Tests on Branches / Frontend Mobile Tests (push) Has been skipped
Run Tests on Branches / Parapharmacy API Tests (push) Successful in 2m2s
Run Tests on Branches / PIP Platform Tests (push) Has been skipped
Run Tests on Branches / Backend Tests (push) Successful in 2m8s
Run Tests on Branches / Detect Changes (push) Successful in 12s
Run Tests on Branches / Frontend Tests (push) Successful in 2m12s
Run Tests on Branches / Frontend Mobile Tests (push) Has been skipped
Run Tests on Branches / Parapharmacy API Tests (push) Successful in 2m2s
Run Tests on Branches / PIP Platform Tests (push) Has been skipped
Run Tests on Branches / Backend Tests (push) Successful in 2m8s
This commit is contained in:
@@ -1,3 +1,4 @@
|
||||
from pydantic import model_validator
|
||||
from pydantic_settings import BaseSettings, SettingsConfigDict
|
||||
|
||||
|
||||
@@ -12,6 +13,7 @@ class Settings(BaseSettings):
|
||||
APP_NAME: str = "PIP - Pharmacy Integration Platform"
|
||||
APP_VERSION: str = "0.1.0"
|
||||
DEBUG: bool = False
|
||||
NODE_ENV: str = "development"
|
||||
|
||||
DATABASE_URL: str = "postgresql+asyncpg://pip:pip@localhost:5432/pip"
|
||||
DATABASE_POOL_SIZE: int = 20
|
||||
@@ -50,6 +52,23 @@ class Settings(BaseSettings):
|
||||
|
||||
HEALTH_CHECK_CACHE_TTL: int = 10
|
||||
|
||||
@model_validator(mode="after")
|
||||
def validate_production_security(self):
|
||||
if self.NODE_ENV.lower() != "production":
|
||||
return self
|
||||
|
||||
if self.JWT_SECRET_KEY == "change-me-in-production":
|
||||
raise ValueError("JWT_SECRET_KEY must be changed in production")
|
||||
|
||||
default_credentials = ("pip:pip@", "pip-secret")
|
||||
if any(value in self.DATABASE_URL or value in self.RABBITMQ_URL for value in default_credentials):
|
||||
raise ValueError("default database or broker credentials are not allowed in production")
|
||||
|
||||
if self.CORS_ALLOW_CREDENTIALS and "*" in self.CORS_ORIGINS:
|
||||
raise ValueError("wildcard CORS_ORIGINS are not allowed with credentials in production")
|
||||
|
||||
return self
|
||||
|
||||
@property
|
||||
def DATABASE_URL_SYNC(self) -> str:
|
||||
return self.DATABASE_URL.replace("+asyncpg", "+psycopg2", 1)
|
||||
|
||||
Reference in New Issue
Block a user