auths.py 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136
  1. from fastapi import Response
  2. from fastapi import Depends, FastAPI, HTTPException, status
  3. from datetime import datetime, timedelta
  4. from typing import List, Union
  5. from fastapi import APIRouter
  6. from pydantic import BaseModel
  7. import time
  8. import uuid
  9. from apps.web.models.auths import (
  10. SigninForm,
  11. SignupForm,
  12. UpdatePasswordForm,
  13. UserResponse,
  14. SigninResponse,
  15. Auths,
  16. )
  17. from apps.web.models.users import Users
  18. from utils.utils import (
  19. get_password_hash,
  20. bearer_scheme,
  21. create_token,
  22. )
  23. from utils.misc import get_gravatar_url
  24. from constants import ERROR_MESSAGES
  25. router = APIRouter()
  26. ############################
  27. # GetSessionUser
  28. ############################
  29. @router.get("/", response_model=UserResponse)
  30. async def get_session_user(cred=Depends(bearer_scheme)):
  31. token = cred.credentials
  32. user = Users.get_user_by_token(token)
  33. if user:
  34. return {
  35. "id": user.id,
  36. "email": user.email,
  37. "name": user.name,
  38. "role": user.role,
  39. "profile_image_url": user.profile_image_url,
  40. }
  41. else:
  42. raise HTTPException(
  43. status_code=status.HTTP_401_UNAUTHORIZED,
  44. detail=ERROR_MESSAGES.INVALID_TOKEN,
  45. )
  46. ############################
  47. # Update Password
  48. ############################
  49. @router.post("/update/password", response_model=bool)
  50. async def update_password(form_data: UpdatePasswordForm, cred=Depends(bearer_scheme)):
  51. token = cred.credentials
  52. session_user = Users.get_user_by_token(token)
  53. if session_user:
  54. user = Auths.authenticate_user(session_user.email, form_data.password)
  55. if user:
  56. hashed = get_password_hash(form_data.new_password)
  57. return Auths.update_user_password_by_id(user.id, hashed)
  58. else:
  59. raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_PASSWORD)
  60. else:
  61. raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
  62. ############################
  63. # SignIn
  64. ############################
  65. @router.post("/signin", response_model=SigninResponse)
  66. async def signin(form_data: SigninForm):
  67. user = Auths.authenticate_user(form_data.email.lower(), form_data.password)
  68. if user:
  69. token = create_token(data={"email": user.email})
  70. return {
  71. "token": token,
  72. "token_type": "Bearer",
  73. "id": user.id,
  74. "email": user.email,
  75. "name": user.name,
  76. "role": user.role,
  77. "profile_image_url": user.profile_image_url,
  78. }
  79. else:
  80. raise HTTPException(400, detail=ERROR_MESSAGES.INVALID_CRED)
  81. ############################
  82. # SignUp
  83. ############################
  84. @router.post("/signup", response_model=SigninResponse)
  85. async def signup(form_data: SignupForm):
  86. if not Users.get_user_by_email(form_data.email.lower()):
  87. try:
  88. role = "admin" if Users.get_num_users() == 0 else "pending"
  89. hashed = get_password_hash(form_data.password)
  90. user = Auths.insert_new_auth(
  91. form_data.email.lower(), hashed, form_data.name, role
  92. )
  93. if user:
  94. token = create_token(data={"email": user.email})
  95. # response.set_cookie(key='token', value=token, httponly=True)
  96. return {
  97. "token": token,
  98. "token_type": "Bearer",
  99. "id": user.id,
  100. "email": user.email,
  101. "name": user.name,
  102. "role": user.role,
  103. "profile_image_url": user.profile_image_url,
  104. }
  105. else:
  106. raise HTTPException(500, detail=ERROR_MESSAGES.CREATE_USER_ERROR)
  107. except Exception as err:
  108. raise HTTPException(500, detail=ERROR_MESSAGES.DEFAULT(err))
  109. else:
  110. raise HTTPException(400, detail=ERROR_MESSAGES.EMAIL_TAKEN)