feat(auth): implement JWT TTL and expiration
added access_token_ttl setting fixed public and private key mismatch while decoding jwt decode_jwt now returns None on expired tokens instead of raising exc generate_pair converts sub to string and uses dynamic expiration
This commit is contained in:
@@ -35,12 +35,15 @@ def generate_jwt(payload: dict[str, Any]) -> str:
|
||||
return jwt.encode(payload, cfg.private_key, "RS256")
|
||||
|
||||
|
||||
def decode_jwt(token: str) -> dict[str, Any]:
|
||||
return jwt.decode(token, cfg.public_key, "RS256")
|
||||
def decode_jwt(token: str) -> dict[str, Any] | None:
|
||||
try:
|
||||
return jwt.decode(token, cfg.public_key, "RS256")
|
||||
except jwt.ExpiredSignatureError:
|
||||
return
|
||||
|
||||
|
||||
def generate_pair(user_id: int, iss: ProvidersType) -> KeyPair:
|
||||
payload = JWTPayload(sub=user_id, iss=iss)
|
||||
payload = JWTPayload(sub=str(user_id), iss=iss)
|
||||
access_token = generate_jwt(payload.model_dump())
|
||||
refresh_token = secrets.token_urlsafe(32)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user