mirror of
https://github.com/hansjone/netx.git
synced 2026-10-10 12:40:44 +08:00
Harden auth with revocable sessions, cookies, and single-login default.
Issue short-lived access JWTs backed by AuthSession rows, HttpOnly cookies with refresh rotation, idle timeout, session management UI, WebCRT ownership caps, and optional Redis login rate limits; new logins revoke other sessions by default. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
ba33ab5c4f
commit
20c2fcd496
34 changed files with 1462 additions and 149 deletions
|
|
@ -12,12 +12,17 @@ class LoginRequest(BaseModel):
|
|||
|
||||
class ChangePasswordRequest(BaseModel):
|
||||
old_password: str = Field(min_length=1, max_length=256)
|
||||
new_password: str = Field(min_length=6, max_length=256)
|
||||
new_password: str = Field(min_length=8, max_length=256)
|
||||
|
||||
|
||||
class RefreshRequest(BaseModel):
|
||||
# Optional when refresh token is sent via HttpOnly cookie.
|
||||
refresh_token: str = Field(default="", max_length=512)
|
||||
|
||||
|
||||
class UserCreateRequest(BaseModel):
|
||||
username: str = Field(min_length=2, max_length=64)
|
||||
password: str = Field(min_length=6, max_length=256)
|
||||
password: str = Field(min_length=8, max_length=256)
|
||||
role: str = Field(default="user")
|
||||
scopes: list[str] | None = None
|
||||
|
||||
|
|
@ -25,7 +30,7 @@ class UserCreateRequest(BaseModel):
|
|||
class UserUpdateRequest(BaseModel):
|
||||
is_active: bool | None = None
|
||||
role: str | None = None
|
||||
password: str | None = Field(default=None, min_length=6, max_length=256)
|
||||
password: str | None = Field(default=None, min_length=8, max_length=256)
|
||||
scopes: list[str] | None = None
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue