Files
felhom.eu/documentation/audits/new-apps-2026-10-01/tools/gm_opds_lock.py
T

30 lines
2.1 KiB
Python

"""gm_opds_lock.py — for R-775's decision: while a stranger's wrong web sign-ins hold every visitor out (429), does an
e-reader's OPDS feed (basic auth, a separate OPDS user) still answer? On 9202 through traefik. The expiry is in throttle.txt.
Evidence: box/grimmory/opds-under-lock.txt."""
import json, os, secrets, time
import walk as w
EVD = f"{w.EV}/box/grimmory"; import os; os.makedirs(EVD, exist_ok=True)
log = open(f"{EVD}/opds-under-lock.txt", "a", buffering=1)
def say(*a):
w.say(*a); log.write(" ".join(map(str, a)) + "\n")
w.login()
t = json.load(open(w.SC + "/seed-tokens-box.json"))["grimmory"]
opw = "Op-" + t["pw"][-10:]
H = ["-sk", "--max-time", "15", "-H", "Host: library.enkisfelhom.hu", "-o", "/dev/null", "-w", "%{http_code}"]
def c(*a):
return (w.sh(["curl"] + H + list(a)).stdout or "").strip()
def login(u, pw):
return c("-H", "Content-Type: application/json", "-X", "POST", "--data", json.dumps({"username": u, "password": pw}), f"{w.BASE}/api/v1/auth/login")
import sys
sys.path.insert(0, "/mnt/5_hdd/felhom.eu/git/app-catalog-felhom.eu/scripts"); import upgrade_fixtures_box as fx
code, tok = fx.Grimmory()._token(w, "library", t["user"], t["pw"])
auth = ["-H", f"Authorization: Bearer {tok}"]
say("OPDS on + an OPDS user:", w.app_curl("library", "/api/v1/settings", *auth, "-H", "Content-Type: application/json", data=json.dumps([{"name": "OPDS_SERVER_ENABLED", "value": True}]), method="PUT")[1],
w.app_curl("library", "/api/v2/opds-users", *auth, "-H", "Content-Type: application/json", data=json.dumps({"username": "olvaso", "password": opw}), method="POST")[1])
say("before: web sign-in ->", login("admin", t["pw"]), "| OPDS feed (olvaso) ->", c("-u", f"olvaso:{opw}", f"{w.BASE}/api/v1/opds"))
say("a stranger's 6 wrong web sign-ins ->", [login("admin", "w" + secrets.token_hex(2)) for _ in range(6)])
t0 = time.time()
say("during the lock: web sign-in (right) ->", login("admin", t["pw"]), "| OPDS feed (right) ->", c("-u", f"olvaso:{opw}", f"{w.BASE}/api/v1/opds"),
"| OPDS wrong ->", c("-u", "olvaso:wrong", f"{w.BASE}/api/v1/opds"))
say("the 15-minute expiry itself was measured earlier (throttle.txt); not waited out again here")