full refresh token
This commit is contained in:
@@ -19,6 +19,20 @@ class AuthService(BaseService):
|
||||
await self.session.commit()
|
||||
return User.model_validate(result)
|
||||
|
||||
async def _tokens_create(self, user_data: TokenData, fingerprint: str):
|
||||
access_token = AuthManager.create_access_token(user_data.model_dump())
|
||||
refresh_token = AuthManager.create_refresh_token()
|
||||
await self.session.auth.create_one({
|
||||
"token": refresh_token,
|
||||
"user_id": user_data.id,
|
||||
"fingerprint": fingerprint
|
||||
})
|
||||
return {
|
||||
"access_token": access_token,
|
||||
"token_type": settings.access_token.token_type,
|
||||
"refresh_token": refresh_token,
|
||||
}
|
||||
|
||||
async def login(self, username: str, password: str, fingerprint: str) -> dict:
|
||||
result = await self.session.user.get_one_or_none(username=username)
|
||||
if result is None:
|
||||
@@ -36,39 +50,20 @@ class AuthService(BaseService):
|
||||
status_code=401,
|
||||
detail="Incorrect username or password",
|
||||
)
|
||||
access_token = AuthManager.create_access_token(token_data.model_dump())
|
||||
refresh_token = AuthManager.create_refresh_token()
|
||||
await self.session.auth.create_one({
|
||||
"token": refresh_token,
|
||||
"user_id": user.id,
|
||||
"fingerprint": fingerprint
|
||||
})
|
||||
await self.session.commit()
|
||||
return {
|
||||
"access_token": access_token,
|
||||
"token_type": settings.access_token.token_type,
|
||||
"refresh_token": refresh_token,
|
||||
}
|
||||
|
||||
async def delete_token(self, token: str) -> None:
|
||||
await self.session.auth.delete_one(token=token)
|
||||
tokens = await self._tokens_create(token_data, fingerprint)
|
||||
await self.session.commit()
|
||||
print(tokens)
|
||||
return tokens
|
||||
|
||||
async def refresh_tokens(self, refresh_token: str, user_data: TokenData, fingerprint: str) -> dict:
|
||||
token_record = await self.session.auth.get_one_or_none(token=refresh_token)
|
||||
if not token_record or token_record.user_id != user_data.id:
|
||||
raise HTTPException(status_code=401, detail="Invalid refresh token")
|
||||
new_access_token = AuthManager.create_access_token(user_data.model_dump())
|
||||
new_refresh_token = AuthManager.create_refresh_token()
|
||||
token = await self._tokens_create(user_data, fingerprint)
|
||||
await self.session.auth.delete_one(token=refresh_token)
|
||||
await self.session.auth.create_one({
|
||||
"token": new_refresh_token,
|
||||
"user_id": user_data.id,
|
||||
"fingerprint": fingerprint
|
||||
})
|
||||
await self.session.commit()
|
||||
return {
|
||||
"access_token": new_access_token,
|
||||
"token_type": settings.access_token.token_type,
|
||||
"refresh_token": new_refresh_token,
|
||||
}
|
||||
return token
|
||||
|
||||
async def delete_token(self, token: str) -> None:
|
||||
await self.session.auth.delete_one(token=token)
|
||||
await self.session.commit()
|
||||
|
||||
Reference in New Issue
Block a user