"""PasswordResetToken and ApiToken models.""" from __future__ import annotations import uuid from datetime import datetime from sqlalchemy import String, DateTime, ForeignKey, func, Index from sqlalchemy.dialects.postgresql import UUID as PGUUID, JSONB from sqlalchemy.orm import Mapped, mapped_column from app.core.db import Base, TenantMixin class PasswordResetToken(Base, TenantMixin): """Token for password reset flow.""" __tablename__ = "password_reset_tokens" id: Mapped[uuid.UUID] = mapped_column( PGUUID(as_uuid=True), primary_key=True, default=uuid.uuid4 ) user_id: Mapped[uuid.UUID] = mapped_column( PGUUID(as_uuid=True), ForeignKey("users.id", ondelete="CASCADE"), nullable=False, index=True ) token_hash: Mapped[str] = mapped_column(String(255), nullable=False, index=True) expires_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), nullable=False) used_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True), nullable=True) class ApiToken(Base, TenantMixin): """API token for programmatic access.""" __tablename__ = "api_tokens" __table_args__ = ( Index("ix_api_tokens_tenant_user", "tenant_id", "user_id"), ) id: Mapped[uuid.UUID] = mapped_column( PGUUID(as_uuid=True), primary_key=True, default=uuid.uuid4 ) user_id: Mapped[uuid.UUID] = mapped_column( PGUUID(as_uuid=True), ForeignKey("users.id", ondelete="CASCADE"), nullable=False ) token_hash: Mapped[str] = mapped_column(String(255), nullable=False, index=True) name: Mapped[str] = mapped_column(String(200), nullable=False) scopes: Mapped[list] = mapped_column(JSONB, nullable=False) expires_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True), nullable=True) last_used_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True), nullable=True) created_at: Mapped[datetime] = mapped_column( DateTime(timezone=True), nullable=False, server_default=func.now() ) revoked_at: Mapped[datetime | None] = mapped_column(DateTime(timezone=True), nullable=True)