- revoke_all_refresh_tokens: add skip_token_hash optional param (exclude
current session while revoking others)
- change_password, enable_totp, disable_totp: call revoke with skip hash
derived from refresh cookie; return sessions_revoked in response and
write to audit log metadata_
- 3 new tests: test_{change_password,enable_totp,disable_totp}_revokes_other_sessions
— all PASSED; 373 total passing, 0 regressions
- Frontend toasts: SettingsAccountTab + TotpEnrollment show
"Other sessions have been terminated." when sessions_revoked > 0
- Companion fixes: rate_limiting get_client_ip refactor, deps/auth.py
request.state.current_user, locustfile refresh-token task removal
- Version bump: 0.1.0 → 0.1.1
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
19 lines
496 B
Python
19 lines
496 B
Python
"""Per-account rate limiter shared across document and cloud routers (D-12)."""
|
|
from __future__ import annotations
|
|
|
|
from fastapi import Request
|
|
from slowapi import Limiter
|
|
|
|
from deps.utils import get_client_ip
|
|
|
|
|
|
def _account_key(request: Request) -> str:
|
|
user = getattr(request.state, "current_user", None)
|
|
if user is not None:
|
|
return str(user.id)
|
|
ip = get_client_ip(request)
|
|
return ip if ip is not None else "anonymous"
|
|
|
|
|
|
account_limiter = Limiter(key_func=_account_key)
|