feat(07.3-02): ES256 JWT algorithm upgrade + startup rotation hook
- config.py: add refresh_token_expire_hours=16, jwt_private_key, jwt_public_key fields (D-01, D-09) - services/auth.py: swap all 4 JWT sites to ES256 via base64-decoded PEM keys; remove HS256 (D-02, D-03) - main.py: add _rotate_tokens_on_algorithm_change lifespan hook — bulk-revokes refresh tokens on algorithm change; idempotent on repeat boots (D-04, D-05) - test_auth_es256.py: promote ES256-01..05 + CFG-01 stubs to 6 passing tests; RM-01..03 remain xfail - docker-compose.yml: inject JWT_PRIVATE_KEY + JWT_PUBLIC_KEY into backend + celery-worker (D-07) - README.md: add JWT key env vars + key generation Python one-liner snippet - .env.example: add JWT_PRIVATE_KEY= and JWT_PUBLIC_KEY= lines - Version bump to 0.1.2
This commit is contained in:
@@ -33,6 +33,10 @@ class Settings(BaseSettings):
|
||||
# Auth / JWT (Phase 2)
|
||||
access_token_expire_minutes: int = 15
|
||||
refresh_token_expire_days: int = 30
|
||||
# ES256 keypair + short-session TTL (Phase 7.3 — D-01, D-09)
|
||||
refresh_token_expire_hours: int = 16 # default short session (16h workday)
|
||||
jwt_private_key: str = "" # base64-encoded PKCS8 PEM; required at runtime
|
||||
jwt_public_key: str = "" # base64-encoded SubjectPublicKeyInfo PEM; required at runtime
|
||||
|
||||
# SMTP (Phase 2 — D-01)
|
||||
smtp_host: str = ""
|
||||
|
||||
Reference in New Issue
Block a user