from fastapi import APIRouter, Depends, HTTPException, status from fastapi.security import OAuth2PasswordRequestForm from sqlalchemy.orm import Session from app.api import deps from app.core.security import create_access_token from app.crud import user as user_crud from app.schemas.token import Token from app.schemas.user import UserCreate, UserRead router = APIRouter(prefix="/auth", tags=["auth"]) @router.post("/register", response_model=UserRead, status_code=status.HTTP_201_CREATED) def register(user_in: UserCreate, db: Session = Depends(deps.get_db)): existing = user_crud.get_by_email(db, user_in.email) if existing: raise HTTPException(status_code=400, detail="Email already registered") return user_crud.create(db, user_in) @router.post("/login", response_model=Token) def login( db: Session = Depends(deps.get_db), form_data: OAuth2PasswordRequestForm = Depends(), ): user = user_crud.authenticate(db, form_data.username, form_data.password) if not user: raise HTTPException(status_code=400, detail="Incorrect email or password") access_token = create_access_token(subject=user.email) return {"access_token": access_token, "token_type": "bearer"}