from __future__ import annotations

from pydantic import BaseModel, EmailStr, Field


class RegisterRequest(BaseModel):
    email: EmailStr
    # AUDIT FIX (StockLab overhaul, security audit): no length/strength constraint existed here
    # before this pass -- a 1-character password would hash and store successfully. min_length=8
    # is a floor, not a full policy (no complexity/breach-list check) -- documented as a known gap
    # in docs/AUDIT_SECURITY.md rather than over-built here. LoginRequest deliberately has NO such
    # constraint: rejecting a login attempt for being "too short" would lock out any account
    # created before this policy existed, which is a worse failure mode than the policy is worth.
    password: str = Field(min_length=8, max_length=256)
    display_name: str | None = None


class LoginRequest(BaseModel):
    email: EmailStr
    password: str


class TokenResponse(BaseModel):
    access_token: str
    refresh_token: str
    token_type: str = "bearer"


class RefreshRequest(BaseModel):
    refresh_token: str
