Repository navigation
Home
Welcome to the pyacct wiki! Pyacct is a compact software service that manages account data, including built-in support for username/password and configuration for other parameters as needed.
The sign-up and log-in API routes do not require authentication, but everything else will require the session UUID passed through the header as authorization (with no indication of the user's serial in the URI).
Accounts are separated into three tables: one with the ID and username, one with the ID and password, and a third join table that connects ID with string key-value pairs. As these keys are more or less arbitrary, there exists a fourth table related to them that maps keys to the attribute details (for now, this just contains: Is it required? Is it sensitive? Is it unique?)
This is for data safety - by separating the accounts' details this way, we ensure that nothing is ever sent back to the user unless it is supposed to. For instance, sensitive data can only be read from the service by the person who submitted it and super users (which for now must be set manually), and passwords can't be read back from the service at all. Passwords are hashed with a salt, which is generated pseudo-randomly on the submission of the password and stored with the hashed password.
The session table contains its UUID, the time it was created, and the last time it was used. A separate join table associates session ID and user ID, the latter of which can be queried by way of the former so that other services can be added on top of this one. Sessions expire after 24 hours, or after they have been unused for an hour.
This service is not natively end-to-end encrypted. Use HTTPS or some other overlying encryption detail.
Primary keys in italics.
