The browser treated sessionStorage as the source of truth for the logged-in user and never verified or invalidated the server-side session cookie: no GET /api/v1/demo/session or POST /api/v1/demo/logout endpoint existed, and a central 401 handler was defined but never wired up. Add both endpoints; the session-check response is marked Cache-Control: no-store to avoid the browser serving a stale "authenticated" response right after logout. AuthProvider now verifies against the server on every mount (sessionStorage only caches presentation state to avoid a login-screen flash), subscribes to a central 401 listener on the API client, and RequireAuth shows a loading state during verification instead of flashing protected content or the wrong role.
39 lines
1.4 KiB
Python
39 lines
1.4 KiB
Python
from functools import lru_cache
|
|
|
|
from pydantic_settings import BaseSettings, SettingsConfigDict
|
|
|
|
|
|
class Settings(BaseSettings):
|
|
model_config = SettingsConfigDict(env_file=".env", extra="ignore")
|
|
|
|
mobilityops_env: str = "development"
|
|
mobilityops_demo_mode: bool = True
|
|
database_url: str = "postgresql+psycopg://mobilityops:mobilityops@db:5432/mobilityops"
|
|
knowledge_provider: str = "demo"
|
|
ragcore_base_url: str = "http://ragcore-api:8000"
|
|
ragcore_tenant: str = "northstar-mobility-demo"
|
|
ragcore_workspace: str = "mobilityops"
|
|
ragcore_collection: str = "internal-procedures"
|
|
ragcore_api_token: str = ""
|
|
ragcore_http_timeout_seconds: float = 5.0
|
|
n8n_webhook_url: str = "http://n8n:5678/webhook/mobilityops-return"
|
|
n8n_callback_token: str = "replace-me-n8n-callback-token"
|
|
n8n_dispatch_enabled: bool = True
|
|
n8n_dispatch_interval_seconds: float = 3.0
|
|
n8n_http_timeout_seconds: float = 5.0
|
|
n8n_max_attempts: int = 5
|
|
app_secret: str = "replace-in-production"
|
|
session_cookie_name: str = "mobilityops_session"
|
|
session_ttl_seconds: int = 60 * 60 * 8
|
|
session_cookie_secure: bool = False
|
|
seed_dir: str = "/app/seed"
|
|
knowledge_dir: str = "/app/knowledge/procedures"
|
|
mcp_hub_service_token: str = "replace-me-mcp-hub-token"
|
|
cors_allow_origins: str = "http://localhost:1228"
|
|
demo_today: str = "2026-08-01"
|
|
|
|
|
|
@lru_cache
|
|
def get_settings() -> Settings:
|
|
return Settings()
|