feat: server-side password security checks
This commit is contained in:
@@ -6,6 +6,7 @@ from typing import Any
|
||||
import jwt
|
||||
from argon2 import PasswordHasher
|
||||
from argon2.exceptions import InvalidHashError, VerificationError, VerifyMismatchError
|
||||
from zxcvbn import zxcvbn
|
||||
|
||||
from config import cfg
|
||||
from schemas.dto import KeyPair
|
||||
@@ -52,3 +53,11 @@ def generate_pair(user_id: int, iss: ProvidersType) -> KeyPair:
|
||||
|
||||
def hash_refresh_token(token: str):
|
||||
return hashlib.sha256(token.encode()).hexdigest()
|
||||
|
||||
|
||||
def estimate_password_strength(password: str) -> bool:
|
||||
if len(password) < cfg.min_password_length:
|
||||
return False
|
||||
|
||||
r = zxcvbn(password)
|
||||
return r.get("score", 0) > cfg.password_security_threshold
|
||||
|
||||
Reference in New Issue
Block a user