You've already forked RekomenciBackend
fix: added validation for crypto_key
This commit is contained in:
+1
-1
@@ -7,7 +7,7 @@ access_log = true
|
|||||||
url = "postgresql+psycopg://username:password@host:port/database"
|
url = "postgresql+psycopg://username:password@host:port/database"
|
||||||
|
|
||||||
[access_token]
|
[access_token]
|
||||||
crypto_key = "..."
|
crypto_key = "..." # 32-byte url-safe base64 key
|
||||||
expires_in = 86400
|
expires_in = 86400
|
||||||
|
|
||||||
[yandex_oauth]
|
[yandex_oauth]
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ access_log = true
|
|||||||
url = "postgresql+psycopg://postgres:postgres@postgres:5432/postgres"
|
url = "postgresql+psycopg://postgres:postgres@postgres:5432/postgres"
|
||||||
|
|
||||||
[access_token]
|
[access_token]
|
||||||
crypto_key = "insecure_token"
|
crypto_key = "YlPGYA-WnyYW8Cd0bFZWPeZjPjfXhrD9P7ciCprYmmc="
|
||||||
expires_in = 86400
|
expires_in = 86400
|
||||||
|
|
||||||
[yandex_oauth]
|
[yandex_oauth]
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ from tomllib import loads
|
|||||||
from typing import dataclass_transform
|
from typing import dataclass_transform
|
||||||
|
|
||||||
from adaptix import P, Retort, loader
|
from adaptix import P, Retort, loader
|
||||||
|
from cryptography.fernet import Fernet
|
||||||
|
|
||||||
from template_project.application.common.containers import SecretString
|
from template_project.application.common.containers import SecretString
|
||||||
|
|
||||||
@@ -24,6 +25,13 @@ class AccessTokenConfiguration:
|
|||||||
crypto_key: str
|
crypto_key: str
|
||||||
expires_in: timedelta
|
expires_in: timedelta
|
||||||
|
|
||||||
|
def __post_init__(self) -> None:
|
||||||
|
try:
|
||||||
|
Fernet(self.crypto_key)
|
||||||
|
except ValueError as error:
|
||||||
|
msg = "access_token.crypto_key must be a valid 32-byte url-safe base64 key"
|
||||||
|
raise ValueError(msg) from error
|
||||||
|
|
||||||
|
|
||||||
@to_configuration
|
@to_configuration
|
||||||
class ServerConfiguration:
|
class ServerConfiguration:
|
||||||
|
|||||||
Reference in New Issue
Block a user