blob: 5f31bd3b6892ee694b7c0ae25621930b11e7b1f3 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
|
import hashlib
import hmac
from pydantic import (
BaseModel,
ConfigDict,
EmailStr,
Field,
TypeAdapter,
computed_field,
)
from jb.config import settings
def email_to_product_user_id(email: str) -> str:
"""Return a deterministic, non-reversible product user ID for an email.
The same normalized email and secret salt always produce the same ID. Keep
the salt private and stable; changing it changes every generated ID.
"""
salt_bytes = settings.magic_token_salt.get_secret_value().encode("utf-8")
if len(salt_bytes) < 32:
raise ValueError("salt must be at least 32 bytes")
if not email.isascii():
raise ValueError("email must contain ASCII characters only")
normalized_email = str(TypeAdapter(EmailStr).validate_python(email)).lower()
return hmac.new(
key=salt_bytes,
msg=normalized_email.encode("utf-8"),
digestmod=hashlib.sha256,
).hexdigest()
class AuthenticatedUser(BaseModel):
"""A user that has been authenticated and exists in THL"""
email: EmailStr = Field()
@computed_field
def product_user_id(self) -> str:
return email_to_product_user_id(self.email)
class AccountCreate(BaseModel):
email: EmailStr = Field()
class AccountLogin(BaseModel):
email: EmailStr = Field()
class MagicLinkExchangeRequest(BaseModel):
model_config = ConfigDict(extra="forbid")
token: str = Field(min_length=1)
class SessionResponse(BaseModel):
session_token: str
token_type: str = "bearer"
expires_in: int
|