Require login for /app/, with a long sliding session so you log in once per device and effectively stay in. - AppLoginRequiredMiddleware gates only /app/; /api/ keeps DRF token auth and /admin/ keeps its own login (a blanket LoginRequired would break token requests, whose user isn't resolved until the view runs). - Login page (styled to the dark palette) via django.contrib.auth.urls; logout control in the nav. - Session: ~1 year cookie, sliding (saved every request), survives browser close. - Dropped every @csrf_exempt now that a real session + CSRF token are in place (HTMX already sends X-CSRFToken). - SECRET_KEY and DEBUG now read from the environment (prod-safe defaults); systemd loads an optional /var/lib/food/.env. - Tests authenticate, plus new coverage: /app/ redirects when logged out, login grants access, /api/ is not caught by the app gate. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
26 lines
714 B
Desktop File
26 lines
714 B
Desktop File
[Unit]
|
|
Description=Food App (Meal Planning API)
|
|
After=network.target
|
|
|
|
[Service]
|
|
Type=notify
|
|
User=openclaw
|
|
Group=openclaw
|
|
WorkingDirectory=/var/lib/food
|
|
Environment="PATH=/var/lib/food/.venv/bin:/usr/bin"
|
|
Environment="DJANGO_SETTINGS_MODULE=food_project.settings"
|
|
# Secrets/config (DJANGO_SECRET_KEY, optional DJANGO_DEBUG) live here, not in git.
|
|
# The leading '-' makes it optional so the service still starts if absent.
|
|
EnvironmentFile=-/var/lib/food/.env
|
|
ExecStart=/var/lib/food/.venv/bin/gunicorn food_project.wsgi:application \
|
|
--bind 127.0.0.1:8042 \
|
|
--workers 2 \
|
|
--timeout 30 \
|
|
--access-logfile - \
|
|
--error-logfile -
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|