5 Commits

Author SHA1 Message Date
26b857ed84 added httpie for tests 2026-07-23 21:50:17 +03:00
be8eb0c485 refresh tokens 0.1.3 2026-07-23 21:44:35 +03:00
eab78b6679 refresh tokens 0.1.2 2026-07-23 20:51:26 +03:00
7199387e6f access tokens 0.1.1 2026-07-23 13:06:44 +03:00
4d61d873b5 Access tokens 0.1.0 2026-07-23 11:13:52 +03:00
16 changed files with 1486 additions and 232 deletions

View File

@@ -1,7 +1,9 @@
from fastapi import FastAPI
from src.web.protected_routes.routes import router as protected_router
import uvicorn
app=FastAPI(root_path="/")
app.include_router(router=protected_router)
@app.get("")
def root()->dict:

1032
poetry.lock generated

File diff suppressed because it is too large Load Diff

View File

@@ -14,12 +14,15 @@ dependencies = [
"uvicorn (>=0.51.0,<0.52.0)",
"gunicorn (>=26.0.0,<27.0.0)",
"fastapi (>=0.139.1,<0.140.0)",
"pydantic (>=2.13.4,<3.0.0)",
"pydantic[email] (>=2.13.4,<3.0.0)",
"pydantic-settings (>=2.14.2,<3.0.0)",
"sqlalchemy (>=2.0.51,<3.0.0)",
"pandas (>=3.0.3,<4.0.0)",
"python-jwt (>=4.1.0,<5.0.0)",
"bcrypt (>=5.0.0,<6.0.0)"
"bcrypt (>=5.0.0,<6.0.0)",
"python-jose (>=3.5.0,<4.0.0)",
"python-multipart (>=0.0.32,<0.0.33)",
"ipython (>=9.15.0,<10.0.0)",
"httpie (>=3.2.4,<4.0.0)"
]

View File

@@ -0,0 +1,64 @@
from uuid import UUID
from src.models.database_models.model import engine, RefreshTokens
from sqlalchemy import and_, not_, select
from sqlalchemy.orm import sessionmaker
from src.models.pydantic_models.model import RefreshTokensOut
class JwtCrudActions:
def __init__(self) -> None:
self.Session=sessionmaker(bind=engine)
def get_token_by_user_id(self, user_id:UUID)->RefreshTokensOut|None:
with self.Session() as session:
with session.begin():
query=select(RefreshTokens).where(and_(RefreshTokens.user_id==user_id, not_(RefreshTokens.is_revoked)))
response=session.scalars(query).one_or_none()
if response is None:
return None
return RefreshTokensOut.model_validate(response)
def get_token_by_id(self, id:UUID)->RefreshTokensOut|None:
with self.Session() as session:
with session.begin():
query=select(RefreshTokens).where(RefreshTokens.id==id)
response=session.scalars(query).one_or_none()
if response is None:
return None
return RefreshTokensOut.model_validate(response)
def create_token(self, data:dict)->None:
with self.Session() as session:
with session.begin():
new_token=RefreshTokens(**data)
response=session.add(new_token)
return response
def update_token(self, old_jti:UUID, new_jti:UUID)->bool:
with self.Session() as session:
with session.begin():
query=select(RefreshTokens).where(RefreshTokens.id==old_jti)
response=session.scalars(query).one()
response.is_revoked=True
response.replaced_by=new_jti
return True
def revoke_all(self, user_id:UUID)->bool:
with self.Session() as session:
with session.begin():
query=select(RefreshTokens).where(RefreshTokens.user_id==user_id)
response=session.scalars(query).all()
for record in response:
record.is_revoked=True
return True
def logout(self,id:UUID)->bool:
with self.Session() as session:
with session.begin():
query=select(RefreshTokens).where(RefreshTokens.id == id)
response=session.scalars(query).one_or_none()
if response is None:
return False
else:
response.is_revoked=True
return True

View File

@@ -0,0 +1,26 @@
from sqlalchemy import select
from src.models.database_models.model import User, engine
from src.models.pydantic_models.model import UserOutDB
from sqlalchemy.orm import sessionmaker
from uuid import UUID
class UsersCrudActions:
def __init__(self) -> None:
self.Session=sessionmaker(bind=engine)
def get_user_by_email(self, email:str)->UserOutDB|None:
with self.Session() as session:
with session.begin():
query=select(User).where(User.email==email)
response=session.scalars(query).one_or_none()
if response is None:
return None
return UserOutDB.model_validate(response)
def get_user_by_id(self, id:UUID)->UserOutDB|None:
with self.Session() as session:
with session.begin():
query=select(User).where(User.id==id)
response=session.scalars(query).one_or_none()
if response is None:
return None
return UserOutDB.model_validate(response)

View File

@@ -0,0 +1,32 @@
"""empty message
Revision ID: 23dd6d3efe4b
Revises: 2f92088cdce4
Create Date: 2026-07-23 13:05:12.553687
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
# revision identifiers, used by Alembic.
revision: str = '23dd6d3efe4b'
down_revision: Union[str, Sequence[str], None] = '2f92088cdce4'
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
"""Upgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###
def downgrade() -> None:
"""Downgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###

View File

@@ -0,0 +1,32 @@
"""empty message
Revision ID: 2f92088cdce4
Revises: 75074097a2a3
Create Date: 2026-07-23 11:05:02.409697
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
# revision identifiers, used by Alembic.
revision: str = '2f92088cdce4'
down_revision: Union[str, Sequence[str], None] = '75074097a2a3'
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
"""Upgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###
def downgrade() -> None:
"""Downgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###

View File

@@ -0,0 +1,50 @@
"""empty message
Revision ID: 385d4efec15f
Revises: 23dd6d3efe4b
Create Date: 2026-07-23 15:03:33.582896
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
# revision identifiers, used by Alembic.
revision: str = '385d4efec15f'
down_revision: Union[str, Sequence[str], None] = '23dd6d3efe4b'
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
"""Upgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
with op.batch_alter_table('refresh_tokens', schema=None) as batch_op:
batch_op.alter_column('id',
existing_type=sa.INTEGER(),
type_=sa.Uuid(),
existing_nullable=False)
batch_op.alter_column('replaced_by',
existing_type=sa.INTEGER(),
type_=sa.Uuid(),
existing_nullable=True)
# ### end Alembic commands ###
def downgrade() -> None:
"""Downgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
with op.batch_alter_table('refresh_tokens', schema=None) as batch_op:
batch_op.alter_column('replaced_by',
existing_type=sa.Uuid(),
type_=sa.INTEGER(),
existing_nullable=True)
batch_op.alter_column('id',
existing_type=sa.Uuid(),
type_=sa.INTEGER(),
existing_nullable=False)
# ### end Alembic commands ###

View File

@@ -0,0 +1,32 @@
"""empty message
Revision ID: 74814eb1b7f8
Revises: 8c136ff14180
Create Date: 2026-07-23 21:06:37.254211
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
# revision identifiers, used by Alembic.
revision: str = '74814eb1b7f8'
down_revision: Union[str, Sequence[str], None] = '8c136ff14180'
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
"""Upgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###
def downgrade() -> None:
"""Downgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###

View File

@@ -0,0 +1,32 @@
"""empty message
Revision ID: 8c136ff14180
Revises: 385d4efec15f
Create Date: 2026-07-23 17:56:26.345954
"""
from typing import Sequence, Union
from alembic import op
import sqlalchemy as sa
# revision identifiers, used by Alembic.
revision: str = '8c136ff14180'
down_revision: Union[str, Sequence[str], None] = '385d4efec15f'
branch_labels: Union[str, Sequence[str], None] = None
depends_on: Union[str, Sequence[str], None] = None
def upgrade() -> None:
"""Upgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###
def downgrade() -> None:
"""Downgrade schema."""
# ### commands auto generated by Alembic - please adjust! ###
pass
# ### end Alembic commands ###

View File

@@ -11,9 +11,9 @@ class Stored(Model):
id:Mapped[int]=mapped_column(primary_key=True, index=True)
doc_id:Mapped[UUID]=mapped_column(default=uuid1, unique=True)
filename:Mapped[str]=mapped_column(String(255), index=True)
created_at:Mapped[datetime]=mapped_column(TIMESTAMP, server_default=func.now())
uploaded_at:Mapped[datetime]=mapped_column(TIMESTAMP,onupdate=func.now(), nullable=True)
doc_date:Mapped[datetime]=mapped_column(TIMESTAMP)
created_at:Mapped[datetime]=mapped_column(TIMESTAMP(timezone=True), server_default=func.now())
uploaded_at:Mapped[datetime]=mapped_column(TIMESTAMP(timezone=True),onupdate=func.now(), nullable=True)
doc_date:Mapped[datetime]=mapped_column(TIMESTAMP(timezone=True))
status:Mapped[str]=mapped_column(String(64))
user_id:Mapped[UUID]=mapped_column(ForeignKey("users.id", ondelete="CASCADE"), index=True)
market_id:Mapped[int]=mapped_column(ForeignKey("markets.id", ondelete="CASCADE"),index=True)

View File

@@ -1,4 +1,4 @@
from sqlalchemy import TIMESTAMP, Table, create_engine, String, Boolean, MetaData, Column, ForeignKey, func
from sqlalchemy import TIMESTAMP, Table, create_engine, String, Boolean, MetaData, Column, ForeignKey, func, Uuid
from sqlalchemy.orm import Mapped, mapped_column, DeclarativeBase, relationship
from uuid import UUID, uuid4
from datetime import datetime
@@ -17,7 +17,7 @@ class Model(DeclarativeBase):
class User(Model):
__tablename__ = "users"
id:Mapped[UUID] = mapped_column(default=uuid4,primary_key=True)
id:Mapped[UUID] = mapped_column(Uuid(as_uuid=True),default=uuid4,primary_key=True)
first_name:Mapped[str] = mapped_column(String(64), index=True)
last_name:Mapped[str]=mapped_column(String(64), index=True)
middle_name:Mapped[str]=mapped_column(String(64), index=True)
@@ -27,10 +27,11 @@ class User(Model):
group:Mapped[list['PermissionsGroups']]=relationship(secondary="user_group", back_populates="user", lazy="selectin")
direct_permissions:Mapped[list['Permissions']]=relationship(secondary="user_direct_permissions", back_populates="users_direct")
direct_permissions:Mapped[list['Permissions']]=relationship(secondary="user_direct_permissions", back_populates="users_direct", lazy="selectin")
refresh_token:Mapped[list['RefreshTokens']]=relationship(back_populates="user")
report:Mapped[list["Stored"]]=relationship(back_populates="user")
def __repr__(self) -> str:
return f"ID: {self.id}, Name: {self.first_name}, Status: {self.status}"
@@ -84,16 +85,16 @@ class RefreshTokens(Model):
__tablename__= "refresh_tokens"
id:Mapped[int]=mapped_column(primary_key=True, index=True)
id:Mapped[UUID]=mapped_column(Uuid(as_uuid=True),primary_key=True, index=True)
user_id:Mapped[UUID]=mapped_column(ForeignKey("users.id", ondelete="CASCADE"), index=True)
token_hash:Mapped[str]=mapped_column(String(255), unique=True)
device_info:Mapped[str]=mapped_column(String(255))
ip_address:Mapped[str]=mapped_column(String(45))
is_revoked:Mapped[bool]=mapped_column(Boolean, default=False)
expires_at:Mapped[datetime]=mapped_column(TIMESTAMP)
created_at:Mapped[datetime]=mapped_column(TIMESTAMP, server_default=func.now())
replaced_by:Mapped[int|None]=mapped_column(ForeignKey("refresh_tokens.id"), nullable=True, default=None)
expires_at:Mapped[datetime]=mapped_column(TIMESTAMP(timezone=True))
created_at:Mapped[datetime]=mapped_column(TIMESTAMP(timezone=True), server_default=func.now())
replaced_by:Mapped[UUID|None]=mapped_column(ForeignKey("refresh_tokens.id"), nullable=True, default=None)
user:Mapped["User"]=relationship(back_populates="refresh_token")

View File

@@ -7,44 +7,14 @@ from uuid import UUID
class Base(BaseModel):
model_config = {"from_attributes": True}
class UserCreate(Base):
first_name:Annotated[str, Field(..., max_length=64,description="first name of the user")]
last_name:Annotated[str, Field(...,max_length=64, description="last name of the user")]
middle_name:Annotated[str, Field(...,max_length=64, description="middle name of the user")]
email:Annotated[EmailStr, Field(...,min_length=5, max_length=255, description="email of the user")]
plain_password:Annotated[str, Field(...,min_length=8,max_length=72, description="plain password of the user")]
status:Annotated[bool, Field(..., description="status of the user")]
permissions:Annotated[list[str], Field(..., description="permissions of the user")]
permission_groups:Annotated[list[str], Field(..., description="permissions groups of the user")]
class UserOut(Base):
id:Annotated[UUID, Field(..., description="Id of the user")]
first_name:Annotated[str, Field(..., max_length=64,description="first name of the user")]
last_name:Annotated[str, Field(..., max_length=64,description="last name of the user")]
middle_name:Annotated[str, Field(..., max_length=64, description="middle name of the user")]
email:Annotated[EmailStr, Field(...,min_length=5, max_length=255, description="email of the user")]
status:Annotated[bool, Field(..., description="status of the user")]
permissions:Annotated[list[str], Field(..., description="permissions of the user")]
permission_groups:Annotated[list[str], Field(..., description="permissions groups of the user")]
class UserUpdate(Base):
first_name:Annotated[str|None, Field(None, max_length=64, description="first name of the user")]
last_name:Annotated[str|None, Field(None, max_length=64,description="last name of the user")]
middle_name:Annotated[str|None, Field(None, max_length=64,description="middle name of the user")]
email:Annotated[EmailStr|None, Field(None, min_length=5, max_length=255, description="email of the user")]
status:Annotated[bool|None, Field(None, description="status of the user")]
permissions:Annotated[list[str]|None, Field(None, description="permissions of the user")]
permission_groups:Annotated[list[str]|None, Field(None, description="permissions groups of the user")]
class PermissionsCreate(Base):
permission:Annotated[str, Field(..., max_length=30, description="permission name")]
class PermissionsOut(Base):
id:Annotated[int, Field(..., description="id of the permission")]
permission:Annotated[str, Field(..., max_length=30, description="permission name")]
@@ -55,18 +25,61 @@ class PermissionsGroupsCreate(Base):
class PermissionsGroupsOut(Base):
id:Annotated[int, Field(..., description="id of the permission group")]
group:Annotated[str, Field(..., max_length=255, description="group name for the permissions")]
class UserCreate(Base):
first_name:Annotated[str, Field(..., max_length=64,description="first name of the user")]
last_name:Annotated[str, Field(...,max_length=64, description="last name of the user")]
middle_name:Annotated[str, Field(...,max_length=64, description="middle name of the user")]
email:Annotated[EmailStr, Field(...,min_length=5, max_length=255, description="email of the user")]
plain_password:Annotated[str, Field(...,min_length=8,max_length=72, description="plain password of the user")]
status:Annotated[bool, Field(..., description="status of the user")]
direct_permissions:Annotated[list[str], Field(..., description="permissions of the user")]
group:Annotated[list[str], Field(..., description="permissions groups of the user")]
class UserOut(Base):
first_name:Annotated[str, Field(..., max_length=64,description="first name of the user")]
last_name:Annotated[str, Field(..., max_length=64,description="last name of the user")]
middle_name:Annotated[str, Field(..., max_length=64, description="middle name of the user")]
email:Annotated[EmailStr, Field(...,min_length=5, max_length=255, description="email of the user")]
direct_permissions:Annotated[list[PermissionsOut], Field(..., description="permissions of the user")]
group:Annotated[list[PermissionsGroupsOut], Field(..., description="permissions groups of the user")]
class UserOutDB(UserOut):
id:Annotated[UUID, Field(..., description="Id of the user")]
status:Annotated[bool, Field(..., description="status of the user")]
hashed_password:Annotated[str, Field(..., description="hashed password of the user")]
class UserUpdate(Base):
first_name:Annotated[str|None, Field(None, max_length=64, description="first name of the user")]
last_name:Annotated[str|None, Field(None, max_length=64,description="last name of the user")]
middle_name:Annotated[str|None, Field(None, max_length=64,description="middle name of the user")]
email:Annotated[EmailStr|None, Field(None, min_length=5, max_length=255, description="email of the user")]
status:Annotated[bool|None, Field(None, description="status of the user")]
direct_permissions:Annotated[list[str]|None, Field(None, description="permissions of the user")]
group:Annotated[list[str]|None, Field(None, description="permissions groups of the user")]
class RefreshTokensCreate(Base):
id:Annotated[UUID, Field(..., description="jti")]
user_id:Annotated[UUID, Field(..., description="foreign key for the user")]
token_hash:Annotated[str, Field(...,max_length=255, description="token hash")]
device_info:Annotated[str, Field(...,max_length=255, description="User device info")]
ip_address:Annotated[str, Field(...,max_length=45, description="ip v4/v6 of the user")]
is_revoked:Annotated[bool|None, Field(None, description="revoke token if logout was made")]
expires_at:Annotated[datetime, Field(..., description="when token is going to be expired")]
class RefreshTokensUpdate(Base):
is_revoked:Annotated[bool, Field(..., description="revoke token if logout was made")]
replaced_by:Annotated[UUID, Field(...,description="old_jti")]
class RefreshTokensOut(Base):
user_id:Annotated[UUID, Field(..., description="foreign key for the user")]
@@ -75,3 +88,7 @@ class RefreshTokensOut(Base):
ip_address:Annotated[str, Field(...,max_length=45, description="ip v4/v6 of the user")]
is_revoked:Annotated[bool|None, Field(None, description="revoke token if logout was made")]
expires_at:Annotated[datetime, Field(..., description="when token is going to be expired")]
replaced_by:Annotated[UUID|None, Field(..., description="Old refresh token")]
class RefreshRequest(Base):
refresh_token:str

181
src/service/auth/auth.py Normal file
View File

@@ -0,0 +1,181 @@
from datetime import datetime, timedelta, timezone
from uuid import UUID
from fastapi import Request
from .jwt import Jwt, Hashes
from src.database.users.crud import UsersCrudActions
from src.database.auth.refresh_tokens import JwtCrudActions
from src.errors.http_errors.errors import Errors
from src.models.pydantic_models.model import RefreshTokensCreate, UserOut
from src.models.configs_read.env import env_settings
class CurrentUser:
def __init__(self) -> None:
self.jwt_service=Jwt()
self.hash=Hashes()
self.crud_db_actions=UsersCrudActions()
self.jwt_db_actions=JwtCrudActions()
self.error=Errors()
def _check(self, form_data_email:str, form_data_password:str,):
'''check user by email'''
user=self.crud_db_actions.get_user_by_email(form_data_email)
if user is None:
raise self.error.credentials_error(detail="Wrong credentials")
if not self.hash.verify_password(plain_password=form_data_password, hashed_password=user.hashed_password):
raise self.error.credentials_error(detail="Wrong credentials")
if user.status is False:
raise self.error.credentials_error(detail="This user is deactivated")
return user
def get_current_user(self, token:str)->UserOut:
payload=self.jwt_service.jwt_decode(token)
if (sub:=payload.get("sub")) is None:
raise self.error.credentials_error(detail="Jwt token is incorrect")
try:
sub=UUID(sub)
except (ValueError, TypeError):
raise self.error.credentials_error(detail="Jwt token is incorrect")
user=self.crud_db_actions.get_user_by_id(sub)
if user is None:
raise self.error.not_found_error(detail="User with this email address not found")
return UserOut.model_validate(user)
def create_access_token(self, user_id:UUID)->str:
'''create new access token if all the checks are successful'''
return self.jwt_service.create_access_token({"sub":str(user_id)})
def create_refresh_token(self,user_id:UUID, request:Request)->str:
token, jti=self.jwt_service.create_refresh_token({"sub":str(user_id)})
try:
jti=UUID(jti)
except (ValueError, TypeError):
raise self.error.credentials_error(detail="Jwt token is incorrect")
'''create new refresh token if all the checks are successful'''
token_record=RefreshTokensCreate(
id=jti,
user_id=user_id,
token_hash=self.hash.token_to_hash(token),
device_info=request.headers.get("user-agent", "unknown"),
ip_address=request.headers.get("x-forwarded-for", "").split(",")[0].strip() or (request.client.host if request.client else "unknown"),
expires_at=datetime.now(timezone.utc)+timedelta(days=env_settings.REFRESH_TOKEN_EXPIRE_DAYS)
)
self.jwt_db_actions.create_token(RefreshTokensCreate.model_dump(token_record))
return token
def refresh_token(self, refresh_token:str, request:Request)->tuple[str, str]:
'''decode old refresh token'''
old_refresh_token=self.jwt_service.jwt_decode(refresh_token)
if (sub:=old_refresh_token.get("sub")) is None or (old_jti:=old_refresh_token.get("jti")) is None:
raise self.error.credentials_error(detail="Jwt token is incorrect")
try:
old_jti=UUID(old_jti)
sub=UUID(sub)
except (ValueError, TypeError):
raise self.error.credentials_error(detail="Jwt token is incorrect")
'''old refresh token check'''
old_record=self.jwt_db_actions.get_token_by_id(old_jti)
if old_record is None:
raise self.error.not_found_error(detail="Token not found")
if old_record.is_revoked:
self.jwt_db_actions.revoke_all(old_record.user_id)
raise self.error.credentials_error(detail="Reuse token detected")
'''sqlite constraints about timezone'''
expires_at=old_record.expires_at
if expires_at.tzinfo is None:
expires_at = expires_at.replace(tzinfo=timezone.utc)
if expires_at<datetime.now(timezone.utc):
raise self.error.credentials_error(detail="Token expired")
'''user check'''
user = self.crud_db_actions.get_user_by_id(sub)
if user is None:
raise self.error.not_found_error(detail="User not found")
if user.status is False:
raise self.error.credentials_error(detail="This user is deactivated")
'''create new refresh token if all the checks are successful'''
new_refresh_token, new_jti=self.jwt_service.create_refresh_token({"sub":str(sub)})
new_access_token=self.create_access_token(user_id=sub)
try:
new_jti=UUID(new_jti)
except (ValueError, TypeError):
raise self.error.credentials_error(detail="Jwt token is incorrect")
'''create database record with the new token'''
new_token_record=RefreshTokensCreate(
id=new_jti,
user_id=sub,
token_hash=self.hash.token_to_hash(new_refresh_token),
device_info=request.headers.get("user-agent", "unknown"),
ip_address=request.headers.get("x-forwarded-for", "").split(",")[0].strip() or (request.client.host if request.client else "unknown"),
expires_at=datetime.now(timezone.utc)+timedelta(days=env_settings.REFRESH_TOKEN_EXPIRE_DAYS),
)
self.jwt_db_actions.create_token(RefreshTokensCreate.model_dump(new_token_record))
'''update old token to deactivate it and assign replaced_by'''
self.jwt_db_actions.update_token(old_jti, new_jti)
return (new_access_token,new_refresh_token)
def logout(self, refresh_token:str)->bool:
'''decode current refresh token'''
payload=self.jwt_service.jwt_decode(refresh_token)
if (jti:=payload.get("jti")) is None:
raise self.error.credentials_error(detail="Invalid Refresh Token")
try:
jti=UUID(jti)
except (ValueError, TypeError):
raise self.error.credentials_error(detail="Jwt token is incorrect")
current_token = self.jwt_db_actions.get_token_by_id(jti)
if current_token is None:
raise self.error.not_found_error(detail="Refresh Token Not Found")
'''logout by assigning revoked flag'''
return self.jwt_db_actions.logout(jti)
def login(self, form_data_email:str, form_data_password:str, request:Request)->tuple[str, str]:
'''revoke all the old refresh tokens'''
user = self._check(form_data_email, form_data_password)
self.jwt_db_actions.revoke_all(user_id=user.id)
'''create access and refresh tokens'''
access_token=self.create_access_token(user_id=user.id)
refresh_token=self.create_refresh_token(user_id=user.id,request=request)
return (access_token, refresh_token)
auth=CurrentUser()

66
src/service/auth/jwt.py Normal file
View File

@@ -0,0 +1,66 @@
from jose import JWTError, jwt
import bcrypt
from src.errors.http_errors.errors import Errors
from datetime import datetime, timedelta, timezone
from src.models.configs_read.env import env_settings
from uuid import uuid4
import hashlib
'''Hash/Check hash'''
class Hashes:
def __init__(self) -> None:
pass
def plain_to_hash(self, plain_password:str)->str:
return bcrypt.hashpw(plain_password.encode("utf-8"), bcrypt.gensalt()).decode("utf-8")
def verify_password(self, plain_password:str, hashed_password:str)->bool:
return bcrypt.checkpw(plain_password.encode("utf-8"), hashed_password.encode("utf-8"))
def token_to_hash(self, token:str)->str:
return hashlib.sha256(token.encode("utf-8")).hexdigest()
'''jwt'''
class Jwt:
def __init__(self) -> None:
self.error=Errors()
def create_access_token(self, data:dict)->str:
user_info=data.copy()
user_info.update({"exp": datetime.now(timezone.utc)+timedelta(minutes=env_settings.ACCESS_TOKEN_EXPIRE_MINUTES),
"token_type":"access"})
print(f"DEBUG: expires at {datetime.now(timezone.utc)+timedelta(minutes=env_settings.ACCESS_TOKEN_EXPIRE_MINUTES)}, minutes={env_settings.ACCESS_TOKEN_EXPIRE_MINUTES}")
return jwt.encode(user_info, env_settings.SECRET_KEY, env_settings.ALGORITHM)
def create_refresh_token(self, data:dict)->tuple[str, str]:
user_info=data.copy()
jti=str(uuid4())
user_info.update({"exp":datetime.now(timezone.utc)+timedelta(days=env_settings.REFRESH_TOKEN_EXPIRE_DAYS),
"token_type":"refresh",
"jti":jti
})
return jwt.encode(user_info, env_settings.SECRET_KEY, env_settings.ALGORITHM), jti
def jwt_decode(self, token:str)->dict:
try:
payload=jwt.decode(token, env_settings.SECRET_KEY, algorithms=[env_settings.ALGORITHM])
if (payload.get("sub")) is None:
raise self.error.credentials_error(detail="Sub block is missing")
except JWTError as e:
raise self.error.credentials_error(detail="JWTerror") from e
return payload

View File

@@ -1,9 +1,55 @@
from fastapi import APIRouter
from fastapi import APIRouter, Depends, Request, Response, Cookie
from fastapi.security import OAuth2PasswordRequestForm, OAuth2PasswordBearer
from src.models.configs_read.env import env_settings
from src.models.pydantic_models.model import UserOut
from src.service.auth.auth import auth
router=APIRouter(prefix="/protected")
oauth2_scheme=OAuth2PasswordBearer(tokenUrl="/protected/token")
oauth2_schema=OAuth2PasswordBearer(tokenUrl="/protected/token", refreshUrl="/protected/refresh")
@router.post("/token")
async def get_access_token(request: Request,response:Response, form_data:OAuth2PasswordRequestForm=Depends())->dict:
access_token, refresh_token=auth.login(form_data_email=form_data.username, form_data_password=form_data.password, request=request)
response.set_cookie(
key="refresh_token",
value=refresh_token,
httponly=True,
secure=True,
samesite="strict",
max_age=env_settings.REFRESH_TOKEN_EXPIRE_DAYS * 24 * 60 * 60
)
return {"access_token": access_token, "token_type": "bearer"}
@router.post("/refresh")
async def get_refresh_token(request:Request,response:Response, refresh_token: str = Cookie())->dict:
access_token, refresh_token= auth.refresh_token(refresh_token=refresh_token,request=request)
response.set_cookie(
key="refresh_token",
value=refresh_token,
httponly=True,
secure=True,
samesite="strict",
max_age=env_settings.REFRESH_TOKEN_EXPIRE_DAYS * 24 * 60 * 60
)
return {"access_token":access_token, "token_type": "bearer"}
async def get_current_user(token:str = Depends(oauth2_schema)) -> UserOut:
return UserOut.model_validate(auth.get_current_user(token))
@router.get("/logout")
async def logout(response:Response,refresh_token: str = Cookie(),current_user:UserOut=Depends(get_current_user))->bool:
response.delete_cookie("refresh_token")
return auth.logout(refresh_token)
@router.get("")
def protected()->dict:
return {"protected router": "Hello, this is a protected router"}
async def protected(current_user:UserOut=Depends(get_current_user))->dict:
return {"protected router": "Hello, this is a protected router"}