Create the concept of API keys to allow third party clients to skip the CAPTCHA check on spot submission

This commit is contained in:
Ian Renton
2026-09-27 16:12:48 +01:00
parent d79c89c74a
commit 5d8cd38351
14 changed files with 155 additions and 42 deletions
+12 -1
View File
@@ -31,8 +31,12 @@ ALLOW_SPOTTING = config.get("allow_spotting", True)
ALLOW_UPSTREAM_SPOTTING = config.get("allow_upstream_spotting", True)
WEB_UI_OPTIONS = config.get("web_ui_options", {})
API_ONLY_MODE = config.get("api_only_mode", False)
API_KEYS = [k for k in (config.get("api_keys") or []) if k]
RECAPTCHA_SECRET_KEY = config.get("recaptcha_secret_key", "")
RECAPTCHA_SITE_KEY = config.get("recaptcha_site_key", "")
# If not explicitly set, protect spot submission if CAPTCHA is configured, as this was the behaviour before the option
# existed. This avoids silently opening up spot submission on servers that upgrade without updating their config.
PROTECT_SPOT_SUBMISSION = config.get("protect_spot_submission", bool(RECAPTCHA_SECRET_KEY))
LOG_LEVEL = config.get("log_level", "INFO")
LOG_WEB_REQUESTS = config.get("log_web_requests", False)
@@ -40,10 +44,17 @@ WEB_UI_OPTIONS["qrz_enabled"] = any(p["class"] == "QRZ" and p["enabled"] for p i
WEB_UI_OPTIONS["hamqth_enabled"] = any(
p["class"] == "HamQTH" and p["enabled"] for p in config["callsign_data_providers"]
)
WEB_UI_OPTIONS["recaptcha_site_key"] = RECAPTCHA_SITE_KEY
# The web UI only needs to show a CAPTCHA if spot submission is protected
WEB_UI_OPTIONS["recaptcha_site_key"] = RECAPTCHA_SITE_KEY if PROTECT_SPOT_SUBMISSION else ""
WEB_UI_OPTIONS["allow_upstream_spotting"] = ALLOW_SPOTTING and ALLOW_UPSTREAM_SPOTTING
if ALLOW_SPOTTING and PROTECT_SPOT_SUBMISSION and not (RECAPTCHA_SITE_KEY and RECAPTCHA_SECRET_KEY):
logger.warning(
"Spot submission is protected but reCAPTCHA keys are not set, so only clients with an API key will be able to submit spots. Users of the web interface will not be able to add spots."
)
def create_provider_from_config(package, config_providers_entry):
"""Utility method to get a provider based on the class specified in its config entry. You must also provide the
package to look for it in, as there are several types of provider. e.g. package "providers.spot", where the config