mirror of
				https://github.com/paperless-ngx/paperless-ngx.git
				synced 2025-10-30 03:56:23 -05:00 
			
		
		
		
	Log failed login attempts
This commit is contained in:
		
							
								
								
									
										15
									
								
								src/paperless/apps.py
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										15
									
								
								src/paperless/apps.py
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,15 @@ | ||||
| from django.apps import AppConfig | ||||
| from django.utils.translation import gettext_lazy as _ | ||||
| from paperless.signals import handle_failed_login | ||||
|  | ||||
|  | ||||
| class PaperlessConfig(AppConfig): | ||||
|     name = "paperless" | ||||
|  | ||||
|     verbose_name = _("Paperless") | ||||
|  | ||||
|     def ready(self): | ||||
|         from django.contrib.auth.signals import user_login_failed | ||||
|  | ||||
|         user_login_failed.connect(handle_failed_login) | ||||
|         AppConfig.ready(self) | ||||
| @@ -416,6 +416,13 @@ if _paperless_url: | ||||
|         # always allow localhost. Necessary e.g. for healthcheck in docker. | ||||
|         ALLOWED_HOSTS = [_paperless_uri.hostname] + ["localhost"] | ||||
|  | ||||
| # For use with trusted proxies | ||||
| _trusted_proxies = os.getenv("PAPERLESS_TRUSTED_PROXIES") | ||||
| if _trusted_proxies: | ||||
|     TRUSTED_PROXIES = _trusted_proxies.split(",") | ||||
| else: | ||||
|     TRUSTED_PROXIES = [] | ||||
|  | ||||
| # The secret key has a default that should be fine so long as you're hosting | ||||
| # Paperless on a closed network.  However, if you're putting this anywhere | ||||
| # public, you should change the key to something unique and verbose. | ||||
|   | ||||
							
								
								
									
										32
									
								
								src/paperless/signals.py
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										32
									
								
								src/paperless/signals.py
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,32 @@ | ||||
| import logging | ||||
|  | ||||
| from django.conf import settings | ||||
| from ipware import get_client_ip | ||||
|  | ||||
| logger = logging.getLogger("paperless.auth") | ||||
|  | ||||
|  | ||||
| # https://docs.djangoproject.com/en/4.1/ref/contrib/auth/#django.contrib.auth.signals.user_login_failed | ||||
| def handle_failed_login(sender, credentials, request, **kwargs): | ||||
|     client_ip, is_routable = get_client_ip( | ||||
|         request, | ||||
|         proxy_trusted_ips=settings.TRUSTED_PROXIES, | ||||
|     ) | ||||
|     if client_ip is None: | ||||
|         logger.info( | ||||
|             f"Login failed for user `{credentials['username']}`." | ||||
|             + " Unable to determine IP address.", | ||||
|         ) | ||||
|     else: | ||||
|         if is_routable: | ||||
|             # We got the client's IP address | ||||
|             logger.info( | ||||
|                 f"Login failed for user `{credentials['username']}`" | ||||
|                 + f" from IP `{client_ip}.`", | ||||
|             ) | ||||
|         else: | ||||
|             # The client's IP address is private | ||||
|             logger.info( | ||||
|                 f"Login failed for user `{credentials['username']}`" | ||||
|                 + f" from private IP `{client_ip}.`", | ||||
|             ) | ||||
		Reference in New Issue
	
	Block a user
	 Michael Shamoon
					Michael Shamoon