fix: enforce authentication for superuser cli command (#9152)

* Enforce authentication for superuser cli command

* shorten security md

* cleanup

* use session_scope

* re-add uvlock

* [autofix.ci] apply automated fixes

* ruff

* update env example

* [autofix.ci] apply automated fixes

* better exception handling

* [autofix.ci] apply automated fixes

* update tests to not use mocks

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes

* Remove old test

* Catch exceptions for typer

* Try output instead of stdout

* Use xdist to run in serial

* Separate create superuse

* [autofix.ci] apply automated fixes

* Ruff

* [autofix.ci] apply automated fixes

* lint

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
This commit is contained in:
Jordan Frazier 2025-08-14 16:29:35 -04:00 • committed by GitHub
commit c188ec113c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
8 changed files with 353 additions and 112 deletions

View file

@ -59,4 +59,36 @@ Setting `LANGFLOW_SKIP_AUTH_AUTO_LOGIN=true` and `LANGFLOW_AUTO_LOGIN=true` skip
`LANGFLOW_SKIP_AUTH_AUTO_LOGIN=true` is the default behavior, so users do not need to change existing workflows in 1.5. To update your workflows to require authentication, set `LANGFLOW_SKIP_AUTH_AUTO_LOGIN=false`.
For more information, see [API keys and authentication](https://docs.langflow.org/api-keys-and-authentication).
For more information, see [API keys and authentication](https://docs.langflow.org/api-keys-and-authentication).
## Security Configuration Guidelines
### Superuser Creation Security
The `langflow superuser` CLI command can present a privilege escalation risk if not properly secured.
#### Security Measures
1. **Authentication Required in Production**
- When `LANGFLOW_AUTO_LOGIN=false`, superuser creation requires authentication
- Use `--auth-token` parameter with a valid superuser API key or JWT token
2. **Disable CLI Superuser Creation**
- Set `LANGFLOW_ENABLE_SUPERUSER_CLI=false` to disable the command entirely
- Strongly recommended for production environments
3. **Secure AUTO_LOGIN Setting**
- Default is `true` for <=1.5. This may change in a future release.
- When `true`, creates default superuser `langflow/langflow` - **ONLY USE IN DEVELOPMENT**
#### Production Security Configuration
```bash
# Recommended production settings
export LANGFLOW_AUTO_LOGIN=false
export LANGFLOW_ENABLE_SUPERUSER_CLI=false
export LANGFLOW_SUPERUSER="<your-superuser-username>"
export LANGFLOW_SUPERUSER_PASSWORD="<your-superuser-password>"
export LANGFLOW_DATABASE_URL="<your-production-database-url>" # e.g. "postgresql+psycopg://langflow:secure_pass@db.internal:5432/langflow"
export LANGFLOW_SECRET_KEY="your-strong-random-secret-key"
```