1. Secure password hashing
Start with the contract: make inputs, outputs and failure behavior explicit before adding infrastructure. This keeps the feature easy to reason about and gives tests a stable boundary.
2. OAuth2 password flow
Apply the pattern through a small vertical slice. Keep framework wiring at the edge and business decisions in focused functions or services that can be tested without starting the whole application.
from datetime import datetime, timedelta, timezone
import jwt
def create_access_token(user_id: int) -> str:
payload = {"sub": str(user_id), "exp": datetime.now(timezone.utc) + timedelta(minutes=15)}
return jwt.encode(payload, settings.jwt_secret, algorithm="HS256")3. Short-lived signed access tokens
Treat failure paths as part of the design. Add bounded resource usage, meaningful errors and a verification step so the behavior remains dependable under real production conditions.
4. Hands-on Exercise
Build the feature
Implement registration, login and a protected /users/me endpoint. Store only password hashes and reject expired or invalid tokens.
Definition of done
- The happy path works through the real HTTP boundary.
- At least one failure path is handled and tested.
- Configuration and secrets stay outside source code.
- The README explains how to run and verify the result.
5. Knowledge Check
Why must JWT payloads never contain secrets?
Show answer
A JWT is signed, not encrypted; clients can decode its payload even though they cannot safely alter it.