Implement persistent API-key authentication

Protect the research lifecycle with X-API-Key validation backed by persistent user and key records. Store only salted scrypt hashes, support expiry and revocation, and expose a local admin CLI for create/list/revoke workflows.

Initialize only the authentication schema at startup, prevent SQL echo from exposing sensitive bound values, and keep health probes public. Add coverage for valid, missing, invalid, expired, and revoked keys.

Document deployment and key administration, update the local CLI to send NSCT_API_KEY, and record the reset handoff state.
This commit is contained in:
faligam
2026-09-06 17:23:05 +02:00
parent 64eb4e8465
commit 1aacf4aa20
14 changed files with 1065 additions and 60 deletions

View File

@@ -41,6 +41,7 @@ postgresql = [
nsct = "nsct.cli:main"
nsct-core = "nsct.cli:main"
nsct-api = "nsct.cli:main_api"
nsct-api-key = "nsct.admin:main"
[tool.hatch.build]
packages = ["src/nsct"]