From ed5313158d73475cc81297cf5af13e5b360afbf9 Mon Sep 17 00:00:00 2001 From: Indiana Date: Mon, 20 Jul 2026 16:00:35 +0000 Subject: [PATCH] fix: address final-review hygiene items (pydantic config, cookie alias, argon2 exception scope) Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_013PphXq1s43DNRj1uWKGXof --- backend/app/deps.py | 2 +- backend/app/routes/auth.py | 2 +- backend/app/schemas.py | 5 ++--- backend/app/security.py | 4 ++-- 4 files changed, 6 insertions(+), 7 deletions(-) diff --git a/backend/app/deps.py b/backend/app/deps.py index 9461bd0..9405dad 100644 --- a/backend/app/deps.py +++ b/backend/app/deps.py @@ -12,7 +12,7 @@ SESSION_COOKIE_NAME = "qm_session" async def get_current_user( - qm_session: str | None = Cookie(default=None), + qm_session: str | None = Cookie(default=None, alias=SESSION_COOKIE_NAME), db: AsyncSession = Depends(get_db), ) -> User: if qm_session is None: diff --git a/backend/app/routes/auth.py b/backend/app/routes/auth.py index 44eb135..6808ad3 100644 --- a/backend/app/routes/auth.py +++ b/backend/app/routes/auth.py @@ -65,7 +65,7 @@ async def login(payload: LoginRequest, response: Response, db: AsyncSession = De @router.post("/logout", status_code=status.HTTP_204_NO_CONTENT) async def logout( response: Response, - qm_session: str | None = Cookie(default=None), + qm_session: str | None = Cookie(default=None, alias=SESSION_COOKIE_NAME), db: AsyncSession = Depends(get_db), ): if qm_session is not None: diff --git a/backend/app/schemas.py b/backend/app/schemas.py index f265258..6c91455 100644 --- a/backend/app/schemas.py +++ b/backend/app/schemas.py @@ -1,6 +1,6 @@ import uuid -from pydantic import BaseModel, Field +from pydantic import BaseModel, ConfigDict, Field class RegisterRequest(BaseModel): @@ -13,8 +13,7 @@ class UserOut(BaseModel): id: uuid.UUID username: str - class Config: - from_attributes = True + model_config = ConfigDict(from_attributes=True) class LoginRequest(BaseModel): diff --git a/backend/app/security.py b/backend/app/security.py index a466dc4..6ed4053 100644 --- a/backend/app/security.py +++ b/backend/app/security.py @@ -1,5 +1,5 @@ from argon2 import PasswordHasher -from argon2.exceptions import VerifyMismatchError +from argon2.exceptions import VerificationError _hasher = PasswordHasher() @@ -11,5 +11,5 @@ def hash_password(password: str) -> str: def verify_password(password: str, password_hash: str) -> bool: try: return _hasher.verify(password_hash, password) - except VerifyMismatchError: + except VerificationError: return False