feat: server-side password security checks

This commit is contained in:
2026-08-18 12:36:22 +07:00
parent 9e209dd695
commit 039babf540
4 changed files with 26 additions and 2 deletions

View File

@@ -6,6 +6,7 @@ from typing import Any
import jwt
from argon2 import PasswordHasher
from argon2.exceptions import InvalidHashError, VerificationError, VerifyMismatchError
from zxcvbn import zxcvbn
from config import cfg
from schemas.dto import KeyPair
@@ -52,3 +53,11 @@ def generate_pair(user_id: int, iss: ProvidersType) -> KeyPair:
def hash_refresh_token(token: str):
return hashlib.sha256(token.encode()).hexdigest()
def estimate_password_strength(password: str) -> bool:
if len(password) < cfg.min_password_length:
return False
r = zxcvbn(password)
return r.get("score", 0) > cfg.password_security_threshold