from datetime import datetime, timedelta from typing import Optional import bcrypt from jose import JWTError, jwt from ..config import get_settings settings = get_settings() def verify_password(plain_password: str, hashed_password: str) -> bool: return bcrypt.checkpw( plain_password.encode('utf-8'), hashed_password.encode('utf-8') ) def get_password_hash(password: str) -> str: return bcrypt.hashpw( password.encode('utf-8'), bcrypt.gensalt() ).decode('utf-8') def create_access_token(data: dict, expires_delta: Optional[timedelta] = None) -> str: to_encode = data.copy() expire = datetime.utcnow() + (expires_delta or timedelta(minutes=settings.access_token_expire_minutes)) to_encode.update({"exp": expire, "type": "access"}) return jwt.encode(to_encode, settings.secret_key, algorithm=settings.algorithm) def create_refresh_token(data: dict) -> str: to_encode = data.copy() expire = datetime.utcnow() + timedelta(days=settings.refresh_token_expire_days) to_encode.update({"exp": expire, "type": "refresh"}) return jwt.encode(to_encode, settings.secret_key, algorithm=settings.algorithm) def decode_token(token: str) -> Optional[dict]: try: payload = jwt.decode(token, settings.secret_key, algorithms=[settings.algorithm]) return payload except JWTError: return None