feat: server-side password security checks
This commit is contained in:
@@ -2,7 +2,12 @@ from fastapi import APIRouter, Depends, HTTPException
|
||||
from fastapi.responses import JSONResponse
|
||||
from sqlalchemy.ext.asyncio import AsyncSession
|
||||
|
||||
from core.secrets import hash_password, hash_refresh_token, verify_password
|
||||
from core.secrets import (
|
||||
estimate_password_strength,
|
||||
hash_password,
|
||||
hash_refresh_token,
|
||||
verify_password,
|
||||
)
|
||||
from db.session import get_db
|
||||
from repositories.sessions import SessionsRepository
|
||||
from repositories.users import UserRepository
|
||||
@@ -27,6 +32,9 @@ async def signup(req: UserRegistration, session: AsyncSession = Depends(get_db))
|
||||
if user:
|
||||
raise HTTPException(status_code=409, detail="User already exists")
|
||||
|
||||
if not estimate_password_strength(req.password):
|
||||
raise HTTPException(422, detail="Password is not secure.")
|
||||
|
||||
password_hash = hash_password(req.password)
|
||||
referal_id = None
|
||||
if req.referal_code:
|
||||
|
||||
Reference in New Issue
Block a user