from rest_framework.exceptions import AuthenticationFailed from rest_framework_simplejwt.authentication import JWTAuthentication from infrasynth.shared.crypto import decrypt from infrasynth.shared.settings_utils import get_setting class CookieJWTAuthentication(JWTAuthentication): """Reads JWT from an HTTP-Only cookie encrypted with Fernet.""" def authenticate(self, request): cookie_name = get_setting("INFRASYNTH_SECURITY", "ACCESS_COOKIE_NAME", "access_token") raw_token = request.COOKIES.get(cookie_name) if not raw_token: return None try: decrypted = decrypt(raw_token) validated_token = self.get_validated_token(decrypted) # type: ignore[arg-type] except Exception: raise AuthenticationFailed("Invalid or expired token.") return self.get_user(validated_token), validated_token