feat: server-side password security checks

This commit is contained in:
2026-08-18 12:36:22 +07:00
parent 9e209dd695
commit 039babf540
4 changed files with 26 additions and 2 deletions

View File

@@ -2,7 +2,12 @@ from fastapi import APIRouter, Depends, HTTPException
from fastapi.responses import JSONResponse
from sqlalchemy.ext.asyncio import AsyncSession
from core.secrets import hash_password, hash_refresh_token, verify_password
from core.secrets import (
estimate_password_strength,
hash_password,
hash_refresh_token,
verify_password,
)
from db.session import get_db
from repositories.sessions import SessionsRepository
from repositories.users import UserRepository
@@ -27,6 +32,9 @@ async def signup(req: UserRegistration, session: AsyncSession = Depends(get_db))
if user:
raise HTTPException(status_code=409, detail="User already exists")
if not estimate_password_strength(req.password):
raise HTTPException(422, detail="Password is not secure.")
password_hash = hash_password(req.password)
referal_id = None
if req.referal_code: