feat: OAuth 2.0 support, server-side safety governor, multi-user auth mode

Publishes server work that shipped in the Android edition but never made
it to this repo:

- Full OAuth 2.0 flow (discovery metadata, dynamic client registration,
  authorize + token endpoints) so claude.ai remote connectors and the
  Android app can authenticate per-user instead of relying on the
  sole-phone fallback.
- Safety governor: server-side heat model (intensity x time) with
  automatic cooldown, per-user overrides via GET/POST /safety/config,
  and governor state piggybacked on heartbeat pings so relay clients
  can display it.
- SB_REQUIRE_MCP_AUTH env flag for multi-user deployments (disables the
  unauthenticated sole-phone fallback).
- requirements-phone.txt and .env.example documenting the new knobs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Aletheia
2026-07-07 20:05:45 +02:00
parent f8a9245f90
commit 6a8bc353c5
10 changed files with 1398 additions and 16 deletions

60
.env.example Normal file
View File

@@ -0,0 +1,60 @@
# Signal Bridge Remote — Environment Configuration
# Copy this to .env and fill in your values.
# ═══ REQUIRED ═══════════════════════════════════════════════════════════
# Generate with: python -c "import secrets; print(secrets.token_hex(32))"
SB_SECRET_KEY=your-secret-key-here
# ═══ Server ═════════════════════════════════════════════════════════════
SB_HOST=0.0.0.0
SB_PORT=8420
# ═══ Auth ═══════════════════════════════════════════════════════════════
# Set to "false" to lock out new registrations after your users are set up
SB_REGISTRATION_OPEN=true
# How long login tokens last (hours)
SB_TOKEN_EXPIRY_HOURS=168
# Set to "true" to require OAuth/token auth on every MCP request (multi-user
# servers). Default "false" keeps the single-user convenience fallback: an
# unauthenticated MCP request is routed to the sole connected phone session.
SB_REQUIRE_MCP_AUTH=false
# ═══ Rate Limiting (anti-harassment) ════════════════════════════════════
# Auth endpoint: strict to prevent credential stuffing
SB_RATE_LIMIT_AUTH=5/minute
# Command endpoint: generous for normal use, blocks floods
SB_RATE_LIMIT_COMMANDS=120/minute
# Global per-IP limit
SB_RATE_LIMIT_GLOBAL=300/minute
# Max WebSocket connections per IP
SB_MAX_WS_PER_IP=3
# Auto-ban after N failed auth attempts (per IP, 1-hour window)
SB_BAN_THRESHOLD=20
# How long bans last (minutes)
SB_BAN_DURATION_MINUTES=30
# ═══ Safety ═════════════════════════════════════════════════════════════
# How often to ping phones (seconds)
SB_HEARTBEAT_INTERVAL=2.0
# How long before declaring a phone dead (seconds)
SB_HEARTBEAT_TIMEOUT=6.0
# ═══ Governor (session intensity limiter) ═══════════════════════════════
# Heat accumulates from intensity × time and dissipates when idle; when it
# hits the threshold the governor forces a cooldown. Server-wide defaults —
# each user can override via GET/POST /safety/config.
SB_GOVERNOR_ENABLED=true
# Heat units/second at intensity 1.0
SB_GOVERNOR_HEAT_RATE=3.0
# Heat units/second dissipated when idle
SB_GOVERNOR_COOL_RATE=2.0
# Heat % that triggers cooldown
SB_GOVERNOR_COOLDOWN_ENTER=90.0
# Heat % at which cooldown may end
SB_GOVERNOR_COOLDOWN_EXIT=30.0
# Minimum seconds a cooldown lasts
SB_GOVERNOR_COOLDOWN_DURATION=30.0
# ═══ Database ═══════════════════════════════════════════════════════════
# SQLite file path (auto-created)
SB_DB_PATH=./signal_bridge.db