Skip to content

Fix login redirects and password hash column capacity - #24

Merged
greyli merged 1 commit into
mainfrom
codex/fix-watchlist-auth-bugs
Sep 20, 2026
Merged

greyli merged 1 commit into
mainfrom
codex/fix-watchlist-auth-bugs

Conversation

@greyli

@greyli greyli commented Sep 20, 2026

Copy link
Copy Markdown
Member

Anonymous requests to protected views currently fail with a BuildError: Flask-Login targets login, but the blueprint registers auth.login. Point login_view at the registered endpoint so /settings redirects to /login?next=%2Fsettings and renders the login form.

The pinned Werkzeug version also generates 162-character password hashes, exceeding the model's String(128) declaration. Widen it to String(256). SQLite accepts the longer values, which hid this schema mismatch; databases enforcing the declared length need enough capacity. This model change does not migrate existing databases.

Add regressions for the complete anonymous redirect and for generated hashes fitting the declared column while validating correct and incorrect passwords. Both tests fail on the original code and pass with these changes.

Validation:

  • All 17 unittest tests pass with the repository's pinned requirements on Python 3.9 (Flask 3.1.1, Flask-Login 0.6.3, Werkzeug 3.1.3).
  • Additional disposable checks passed for all anonymous protected routes, malformed forms, missing movies, and init-db, init-db --drop, admin creation/update, and forge.
  • Inspected factory, configuration/database paths, main/auth routes, models, templates, and CLI commands; no further reproducible failures found in this bounded audit. Configuration paths were inspected without opening development/production databases.
  • Tests used in-memory SQLite. No live database, MySQL/PostgreSQL integration, hosting, or deployment changes were performed.

@greyli
greyli merged commit 5dd104f into main Sep 20, 2026
5 checks passed
@greyli
greyli deleted the codex/fix-watchlist-auth-bugs branch September 20, 2026 06:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant