_set_security_context. Internal helper function. This docstring was expanded to make future maintenance easier. Returns: Varies.
()
| 1513 | fp = secrets.token_urlsafe(24) |
| 1514 | if resp is not None: |
| 1515 | # 180 days |
| 1516 | resp.set_cookie(DEVICE_FP_COOKIE, fp, max_age=180*24*3600, httponly=True, samesite="Lax", secure=request.is_secure) |
| 1517 | return fp |
| 1518 | |
| 1519 | def _set_device_token_cookie(resp, token: str): |
| 1520 | # 180 days |
| 1521 | resp.set_cookie(DEVICE_TOKEN_COOKIE, token, max_age=180*24*3600, httponly=True, samesite="Lax", secure=request.is_secure) |
| 1522 | |
| 1523 | def _clear_device_token_cookie(resp): |
| 1524 | resp.delete_cookie(DEVICE_TOKEN_COOKIE) |
| 1525 | # Do not delete fp cookie so device approval flow can work. |
| 1526 | |
| 1527 | def _trusted_device_lookup(fp: str, token: str) -> Optional[str]: |
| 1528 | """Return username if token matches a trusted device and is approved.""" |
| 1529 | if not fp or not token: |
| 1530 | return None |
| 1531 | th = _sha256_hex(token) |
| 1532 | if not th: |
nothing calls this directly
no test coverage detected