fix(backend): adressed copilot review

This commit is contained in:
ribardej
2025-10-23 19:16:14 +02:00
parent 584c090b80
commit b0cd7030d8
2 changed files with 1 additions and 29 deletions

View File

@@ -56,15 +56,14 @@ async def auth_guard(request: Request, call_next):
# Enforce revoked/expired JWTs are rejected globally
token = extract_bearer_token(request)
if token:
from fastapi import Response, status as _status
# Deny if token is revoked
if is_token_revoked(token):
from fastapi import Response, status as _status
return Response(status_code=_status.HTTP_401_UNAUTHORIZED)
# Deny if token is expired or invalid
try:
decode_and_verify_jwt(token, SECRET)
except Exception:
from fastapi import Response, status as _status
return Response(status_code=_status.HTTP_401_UNAUTHORIZED)
return await call_next(request)