from typing import Optional from .auth_access_token_read_access_token import access_denied from .auth_access_token_types import AccessCheck def confirm_access_token(check: AccessCheck, current_token_version: Optional[int], revoked: bool) -> AccessCheck: """The last word on a token read_access_token accepted, once the caller has looked up the user and the revoked list: a logged-out token, or one issued before the user's token version was bumped (a password change), no longer stands.""" if current_token_version is not None and ( isinstance(current_token_version, bool) or not isinstance(current_token_version, int) ): raise TypeError("currentTokenVersion must be a whole number or null") if not isinstance(revoked, bool): raise TypeError("revoked must be true or false") if not check.ok: return check if current_token_version is None: return access_denied("user_not_found", "the token's user no longer exists") if revoked: return access_denied("token_revoked", "the token has been revoked by logging out") if check.token_version != current_token_version: return access_denied( "token_revoked", "the token was issued before the user's tokens were revoked (password changed)" ) return check