Files
rengine/backend/app/core/security.py
T
Yogesh Ojha 443f73af89 refactor: restructure backend codebase and implement user authentication features
- Update Dockerfile to copy shared directory and dependency files
- Create new README.md file
- Refactor database session management and security imports
- Implement user authentication routes and user management endpoints
- Add configuration settings for application and database
- Set up logging configuration for backend services
- Update docker-compose for improved service management
2026-01-24 14:26:10 +05:30

99 lines
2.3 KiB
Python

from datetime import datetime, timedelta, timezone
from typing import Any
from argon2 import PasswordHasher
from argon2.exceptions import VerifyMismatchError
from jose import jwt, JWTError
from app.config import settings
ph = PasswordHasher(
time_cost=2,
memory_cost=65536,
parallelism=4,
hash_len=32,
salt_len=16,
)
def hash_password(password: str) -> str:
"""
Hash a password using Argon2id.
Args:
password: Plain text password to hash
Returns:
Argon2 hash as a string
"""
return ph.hash(password)
def verify_password(plain_password: str, hashed_password: str) -> bool:
"""
Verify a password against its hash.
Args:
plain_password: Plain text password to verify
hashed_password: Argon2 hash to verify against
Returns:
True if password matches, False otherwise
"""
try:
ph.verify(hashed_password, plain_password)
return True
except VerifyMismatchError:
return False
def create_token(
subject: str | Any,
token_type: str,
expires_delta: timedelta,
) -> str:
"""Create a JWT token with the given subject and expiration."""
expire = datetime.now(timezone.utc) + expires_delta
to_encode = {
"exp": expire,
"sub": str(subject),
"type": token_type,
}
return jwt.encode(to_encode, settings.SECRET_KEY, algorithm=settings.ALGORITHM)
def create_access_token(subject: str | Any) -> str:
"""Create an access token for the given subject."""
return create_token(
subject=subject,
token_type="access",
expires_delta=timedelta(minutes=settings.ACCESS_TOKEN_EXPIRE_MINUTES),
)
def create_refresh_token(subject: str | Any) -> str:
"""Create a refresh token for the given subject."""
return create_token(
subject=subject,
token_type="refresh",
expires_delta=timedelta(days=settings.REFRESH_TOKEN_EXPIRE_DAYS),
)
def decode_token(token: str) -> dict | None:
"""
Decode and validate a JWT token.
Returns:
Decoded payload dict if valid, None otherwise
"""
try:
payload = jwt.decode(
token,
settings.SECRET_KEY,
algorithms=[settings.ALGORITHM],
)
return payload
except JWTError:
return None