Отзыв JWT при выходе и смене пароля

logout отзывает предъявленный токен по jti (in-memory denylist до exp);
смена и сброс пароля инкрементят users.token_version (claim ver в JWT,
сверка в auth/deps) — все прежние сессии отзываются. Своё устройство при
смене пароля остаётся в сессии (перевыдача cookie). Миграция 0013. #57

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XfTsytzT6TojfmprRDKiV6
This commit is contained in:
2026-09-13 17:09:57 +03:00
co-authored by Claude Opus 4.8
parent d84cef2491
commit 3f8667b561
12 changed files with 236 additions and 12 deletions
+3 -2
View File
@@ -41,7 +41,7 @@ def admin_login(
session: Session = Depends(get_session),
) -> s.AdminMe:
admin = admin_service.authenticate_admin(session, body.username, body.password)
security.set_admin_session(response, admin.id) # type: ignore[arg-type]
security.set_admin_session(response, admin.id, admin.token_version) # type: ignore[arg-type]
audit_service.record(
session,
actor_id=admin.id,
@@ -56,7 +56,8 @@ def admin_login(
@router.post("/auth/logout", response_model=s.OkResponse)
def admin_logout(response: Response) -> s.OkResponse:
def admin_logout(request: Request, response: Response) -> s.OkResponse:
security.revoke_session_token(request, security.ADMIN_COOKIE, security.AUDIENCE_ADMIN)
security.clear_admin_session(response)
return s.OkResponse()