All checks were successful
Chore App Build and Push Docker Images / build-and-push (push) Successful in 1m4s
- Added `requireDirty` prop to `EntityEditForm` for dirty state management. - Updated `ChildEditView` to handle initial data loading and image selection more robustly. - Refactored `ChildView` to remove unused reward dialog logic and prevent API calls in child mode. - Improved type definitions for form fields and initial data in `ChildEditView`. - Enhanced error handling in form submissions across components. - Implemented cross-tab logout synchronization on password reset in the auth store. - Added tests for login and entity edit form functionalities to ensure proper behavior. - Introduced global fetch interceptor for handling unauthorized responses. - Documented password reset flow and its implications on session management.
53 lines
1.6 KiB
Python
53 lines
1.6 KiB
Python
import jwt
|
|
import re
|
|
from db.db import users_db
|
|
from tinydb import Query
|
|
from flask import request, current_app, jsonify
|
|
|
|
from events.sse import send_event_to_user
|
|
|
|
|
|
def normalize_email(email: str) -> str:
|
|
"""Normalize email for uniqueness checks (Gmail: remove dots and +aliases)."""
|
|
email = email.strip().lower()
|
|
if '@' not in email:
|
|
return email
|
|
local, domain = email.split('@', 1)
|
|
if domain in ('gmail.com', 'googlemail.com'):
|
|
local = local.split('+', 1)[0].replace('.', '')
|
|
return f"{local}@{domain}"
|
|
|
|
def sanitize_email(email):
|
|
return email.replace('@', '_at_').replace('.', '_dot_')
|
|
|
|
def get_current_user_id():
|
|
token = request.cookies.get('token')
|
|
if not token:
|
|
return None
|
|
try:
|
|
payload = jwt.decode(token, current_app.config['SECRET_KEY'], algorithms=['HS256'])
|
|
user_id = payload.get('user_id')
|
|
if not user_id:
|
|
return None
|
|
token_version = payload.get('token_version', 0)
|
|
user = users_db.get(Query().id == user_id)
|
|
if not user:
|
|
return None
|
|
if token_version != user.get('token_version', 0):
|
|
return None
|
|
return user_id
|
|
except jwt.InvalidTokenError:
|
|
return None
|
|
|
|
def get_validated_user_id():
|
|
user_id = get_current_user_id()
|
|
if not user_id or not users_db.get(Query().id == user_id):
|
|
return None
|
|
return user_id
|
|
|
|
def send_event_for_current_user(event):
|
|
user_id = get_current_user_id()
|
|
if not user_id:
|
|
return jsonify({'error': 'Unauthorized'}), 401
|
|
send_event_to_user(user_id, event)
|
|
return None |