Простая регистрация: /register, автовход, ALLOW_REGISTRATION, лимит для новых

This commit is contained in:
apuc committed 2026-09-16 12:30:30 +03:00
1 parent adf6fd24f7
commit 963c29084c
5 files changed
+140 -2

No files matched your search

+6
View File
@@ -15,3 +15,9 @@ HH_HEADLESS=0
# На сервере без sandbox (root/контейнер): 1
HH_NO_SANDBOX=0
# Регистрация: 1 = открытая (любой может создать аккаунт), 0 = только через manage_users.py
ALLOW_REGISTRATION=1
# Дневной лимит генераций для самостоятельно зарегистрированных пользователей
REGISTER_LLM_LIMIT=50
+16 -1
View File
@@ -69,7 +69,9 @@
- ОС: **Debian 12 / Ubuntu 22.04+**, есть **root**
- Домен или статический IP; порты **22, 80, 443** открыты
- Круг пользователей небольшой (2–10 человек), пользователей создаёт владелец (без открытой регистрации)
- Круг пользователей небольшой (2–10 человек). Два варианта:
- **Открытая регистрация** (по умолчанию): любой может создать аккаунт на странице `/register`
- **Закрытая** (`ALLOW_REGISTRATION=0` в `.env`): пользователей создаёт владелец через `manage_users.py`
---
@@ -154,6 +156,19 @@ systemctl enable --now xvfb
## Этап 4 — пользователи
**Вариант А — открытая регистрация** (по умолчанию, `ALLOW_REGISTRATION=1`):
любой посетитель создаёт аккаунт сам на странице `/register` (логин + пароль,
сразу входит). Лимит генераций для таких пользователей — `REGISTER_LLM_LIMIT`
(по умолчанию 50 в день). Владельца всё равно стоит создать через CLI:
```bash
# Владелец (лимит 50 генераций в день)
/opt/hh_auto/.venv/bin/python /opt/hh_auto/manage_users.py add admin --password СЛОЖНЫЙ_ПАРОЛЬ --limit 50
```
**Вариант Б — закрытая регистрация** (`ALLOW_REGISTRATION=0` в `.env`):
пользователей создаёт только владелец:
```bash
# Владелец (лимит 50 генераций в день)
/opt/hh_auto/.venv/bin/python /opt/hh_auto/manage_users.py add admin --password СЛОЖНЫЙ_ПАРОЛЬ --limit 50
+4
View File
@@ -29,6 +29,9 @@
button:hover { background: var(--accent-hover); }
.error { color: var(--red); font-size: 13px; text-align: center; margin-top: 10px;
min-height: 20px; }
.link { text-align: center; margin-top: 14px; font-size: 13px; }
.link a { color: var(--accent); text-decoration: none; }
.link a:hover { color: var(--accent-hover); }
</style>
</head>
<body>
@@ -39,6 +42,7 @@
<input type="password" id="password" placeholder="Пароль" autocomplete="current-password">
<button onclick="doLogin()">Войти</button>
<div id="msg" class="error"></div>
<div class="link">Нет аккаунта? <a href="/register">Зарегистрироваться</a></div>
</div>
<script>
async function doLogin() {
+72
View File
@@ -0,0 +1,72 @@
<!DOCTYPE html>
<html lang="ru">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Регистрация — hh.ru автоотклик</title>
<style>
:root {
--bg: #0f1117; --card: #1a1d27; --border: #2a2f3a; --text: #e5e7eb;
--muted: #9ca3af; --accent: #3b82f6; --accent-hover: #60a5fa;
--input-bg: #12141c; --red: #ef4444;
}
* { box-sizing: border-box; margin: 0; padding: 0; }
body { font-family: system-ui, -apple-system, "Segoe UI", Roboto, sans-serif;
background: var(--bg); color: var(--text); font-size: 14px;
display: flex; align-items: center; justify-content: center;
min-height: 100vh; }
.login-box { background: var(--card); border: 1px solid var(--border);
border-radius: 12px; padding: 32px; width: 100%; max-width: 360px; }
.login-box h1 { font-size: 18px; text-align: center; margin-bottom: 4px; }
.login-box .muted { text-align: center; font-size: 13px; margin-bottom: 20px; }
input { width: 100%; padding: 10px 12px; border: 1px solid var(--border);
border-radius: 8px; font-size: 14px; font-family: inherit;
background: var(--input-bg); color: var(--text); margin-bottom: 12px; }
input:focus { outline: none; border-color: var(--accent); }
button { width: 100%; padding: 10px; border: none; border-radius: 8px;
cursor: pointer; font-size: 14px; background: var(--accent); color: #fff;
font-weight: 500; }
button:hover { background: var(--accent-hover); }
.error { color: var(--red); font-size: 13px; text-align: center; margin-top: 10px;
min-height: 20px; }
.link { text-align: center; margin-top: 14px; font-size: 13px; }
.link a { color: var(--accent); text-decoration: none; }
.link a:hover { color: var(--accent-hover); }
</style>
</head>
<body>
<div class="login-box">
<h1>hh.ru автоотклик</h1>
<p class="muted">Регистрация</p>
<input type="text" id="username" placeholder="Логин (3-30 символов)" autocomplete="username" autofocus>
<input type="password" id="password" placeholder="Пароль (мин. 6 символов)" autocomplete="new-password">
<input type="password" id="confirm" placeholder="Повторите пароль" autocomplete="new-password">
<button onclick="doRegister()">Зарегистрироваться</button>
<div id="msg" class="error"></div>
<div class="link">Уже есть аккаунт? <a href="/login">Войти</a></div>
</div>
<script>
async function doRegister() {
const msg = document.getElementById('msg');
msg.textContent = '';
try {
const resp = await fetch('/register', {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
username: document.getElementById('username').value,
password: document.getElementById('password').value,
confirm: document.getElementById('confirm').value,
}),
});
const data = await resp.json();
if (!resp.ok) { msg.textContent = data.error || 'Ошибка регистрации'; return; }
window.location = '/';
} catch (e) { msg.textContent = 'Ошибка сети'; }
}
document.getElementById('confirm').addEventListener('keydown', e => {
if (e.key === 'Enter') doRegister();
});
</script>
</body>
</html>
+42 -1
View File
@@ -22,7 +22,7 @@ from functools import wraps
from flask import (Flask, jsonify, render_template, request, session,
redirect, url_for, send_file)
from werkzeug.security import check_password_hash
from werkzeug.security import check_password_hash, generate_password_hash
from hh_search import (search_vacancies, fetch_vacancy_details, fetch_my_resumes,
parse_cookies, get_proxies)
@@ -208,6 +208,47 @@ def login_page():
return render_template("login.html")
@app.route("/register", methods=["GET", "POST"])
def register_page():
"""Простая регистрация: логин + пароль. Отключается через ALLOW_REGISTRATION=0."""
if os.environ.get("ALLOW_REGISTRATION", "1") != "1":
if request.method == "POST":
return jsonify({"error": "Регистрация отключена"}), 403
return redirect(url_for("login_page"))
if request.method == "POST":
data = request.get_json(force=True)
username = (data.get("username") or "").strip()
password = data.get("password") or ""
confirm = data.get("confirm") or ""
# Проверки
if not re.match(r"^[a-zA-Z0-9_.-]{3,30}$", username):
return jsonify({"error": "Логин: 3-30 символов, буквы/цифры/точка/дефис/подчёркивание"}), 400
if len(password) < 6:
return jsonify({"error": "Пароль: минимум 6 символов"}), 400
if password != confirm:
return jsonify({"error": "Пароли не совпадают"}), 400
users = load_users()
if username in users:
return jsonify({"error": "Логин уже занят"}), 409
limit = int(os.environ.get("REGISTER_LLM_LIMIT", "50") or 0)
users[username] = {
"password_hash": generate_password_hash(password),
"llm_limit": limit,
"llm_usage": {},
"created": date.today().isoformat(),
"registered": True,
}
save_users(users)
os.makedirs(os.path.join(USERS_DIR, username, "accounts"), exist_ok=True)
session["user"] = username # сразу входим
return jsonify({"ok": True, "limit": limit})
return render_template("register.html")
@app.route("/logout")
def logout():
session.clear()