Files
rentman-clone/backend/app/core/security.py
T
Agent Zero e4830549ac fix: 7 Bugs behoben – Backend+Frontend lauffähig getestet
Backend-Fixes:
- vehicles-Relation in Account-Model ergänzt (500er bei Auth)
- security.py: bcrypt direkt statt passlib (bcrypt 5.x-Kompatibilität)
- auth.py Login: selectinload(User.role) gegen Lazy-Loading-500er
- equipment_group.py: LocationRef-Import via TYPE_CHECKING

Frontend-Fixes:
- api.ts: Python-Docstring durch JS-Kommentar ersetzt
- AppLayout.tsx: AddressBook→Contact (existiert nicht in lucide-react)
- package.json: axios-Dependency ergänzt

Tests bestanden:
- Health 200, Register 201, Login 200, Projects CRUD 200, alle API-Listen 200
- tsc --noEmit: sauber, vite build: erfolgreich
2026-05-31 20:49:10 +00:00

47 lines
1.8 KiB
Python

"""Security helpers: password hashing and JWT token management."""
from datetime import datetime, timedelta, timezone
from typing import Any
import bcrypt
from jose import jwt
from app.core.config import settings
def verify_password(plain_password: str, hashed_password: str) -> bool:
"""Verify a plaintext password against a bcrypt hash."""
return bcrypt.checkpw(
plain_password.encode("utf-8"), hashed_password.encode("utf-8")
)
def get_password_hash(password: str) -> str:
"""Hash a password using bcrypt."""
return bcrypt.hashpw(password.encode("utf-8"), bcrypt.gensalt()).decode("utf-8")
def create_access_token(subject: str | Any, expires_delta: timedelta | None = None) -> str:
"""Create a short-lived JWT access token."""
if expires_delta is None:
expires_delta = timedelta(minutes=settings.ACCESS_TOKEN_EXPIRE_MINUTES)
now = datetime.now(timezone.utc)
expire = now + expires_delta
to_encode = {"exp": expire, "sub": str(subject), "iat": now, "type": "access"}
return jwt.encode(to_encode, settings.JWT_SECRET_KEY, algorithm=settings.JWT_ALGORITHM)
def create_refresh_token(subject: str | Any, expires_delta: timedelta | None = None) -> str:
"""Create a long-lived JWT refresh token."""
if expires_delta is None:
expires_delta = timedelta(minutes=settings.REFRESH_TOKEN_EXPIRE_MINUTES)
now = datetime.now(timezone.utc)
expire = now + expires_delta
to_encode = {"exp": expire, "sub": str(subject), "iat": now, "type": "refresh"}
return jwt.encode(to_encode, settings.JWT_SECRET_KEY, algorithm=settings.JWT_ALGORITHM)
def verify_token(token: str) -> dict:
"""Decode and verify a JWT token. Returns the payload dict."""
return jwt.decode(token, settings.JWT_SECRET_KEY, algorithms=[settings.JWT_ALGORITHM])