Functional Weave
Code in Python

auth.access-token@1.0.0

impl/python/confirm_access_token.py

1,320 bytes · the Python implementation · view raw

Imports name this capability’s declared dependencies, which fune builds next to it in your project; each one links to its page.

from typing import Optional

from .auth_access_token_read_access_token import access_denied  ← readAccessToken, another function of this group · built into the same file, even by a slim install
from .auth_access_token_types import AccessCheck


def confirm_access_token(check: AccessCheck, current_token_version: Optional[int], revoked: bool) -> AccessCheck:
    """The last word on a token read_access_token accepted, once the caller has
    looked up the user and the revoked list: a logged-out token, or one issued
    before the user's token version was bumped (a password change), no longer
    stands."""
    if current_token_version is not None and (
        isinstance(current_token_version, bool) or not isinstance(current_token_version, int)
    ):
        raise TypeError("currentTokenVersion must be a whole number or null")
    if not isinstance(revoked, bool):
        raise TypeError("revoked must be true or false")
    if not check.ok:
        return check
    if current_token_version is None:
        return access_denied("user_not_found", "the token's user no longer exists")
    if revoked:
        return access_denied("token_revoked", "the token has been revoked by logging out")
    if check.token_version != current_token_version:
        return access_denied(
            "token_revoked", "the token was issued before the user's tokens were revoked (password changed)"
        )
    return check