fix: password_history.id → INTEGER monotonic (детерминированная обрезка)
Грабля: created_at в SQLite точен до секунды — 7 быстрых смен дают равные метки, а secondary-сортировка по UUID-id случайна → «последние 5» выбираются произвольно (флакущий тест + неверно хранимая история). id теперь autoincrement (обрезка order_by id desc), UUID остаётся как public_id. Миграция 010 обновлена (таблица только на CT108, пересоздаётся миграцией заново — см. деплой).
This commit is contained in:
@@ -83,7 +83,8 @@ def record_password_change(db: Session, user: User, new_hash: str,
|
||||
|
||||
В историю кладётся ПРЕДЫДУЩИЙ хэш (previous_hash — хэш, который заменяют),
|
||||
чтобы его нельзя было вернуть, пока он не выпал из password_history_count
|
||||
последних записей. Обрезка хранит ровно password_history_count записей.
|
||||
последних записей. Обрезка хранит ровно password_history_count записей;
|
||||
порядок — по monotonic id (created_at в SQLite точен до секунды).
|
||||
"""
|
||||
history_count = int(get_setting(db, 'password_history_count', '5'))
|
||||
old_hash = previous_hash if previous_hash is not None else user.hashed_password
|
||||
@@ -93,8 +94,7 @@ def record_password_change(db: Session, user: User, new_hash: str,
|
||||
if history_count > 0:
|
||||
keep = (db.query(PasswordHistoryEntry.id)
|
||||
.filter(PasswordHistoryEntry.user_id == user.id)
|
||||
.order_by(PasswordHistoryEntry.created_at.desc(),
|
||||
PasswordHistoryEntry.id.desc())
|
||||
.order_by(PasswordHistoryEntry.id.desc())
|
||||
.limit(history_count).all())
|
||||
keep_ids = [row[0] for row in keep]
|
||||
if keep_ids:
|
||||
|
||||
Reference in New Issue
Block a user