{"record":{"id":"7e1981f02acf6620","repo":"affaan-m/ECC","slug":"inactive-user","errorCode":null,"errorMessage":"Inactive user","messagePattern":"Inactive user","errorType":"http","errorClass":"HTTPException","httpStatus":403,"severity":"error","filePath":"skills/fastapi-patterns/SKILL.md","lineNumber":216,"sourceCode":"        payload = jwt.decode(token, settings.secret_key, algorithms=[settings.algorithm])\n        subject = payload.get(\"sub\")\n        if subject is None:\n            raise credentials_exception\n        user_id = int(subject)\n    except (JWTError, TypeError, ValueError):\n        raise credentials_exception\n\n    user = await db.get(User, user_id)\n    if user is None:\n        raise credentials_exception\n    return user\n\n\nasync def get_current_active_user(\n    current_user: Annotated[User, Depends(get_current_user)],\n) -> User:\n    if not current_user.is_active:\n        raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=\"Inactive user\")\n    return current_user\n\n\nDbDep = Annotated[AsyncSession, Depends(get_db)]\nCurrentUserDep = Annotated[User, Depends(get_current_user)]\nActiveUserDep = Annotated[User, Depends(get_current_active_user)]\n```\n\n---\n\n## Router and Endpoint Design\n\n```python\n# app/routers/users.py\nfrom typing import Annotated\nfrom fastapi import APIRouter, HTTPException, Query, status\nfrom fastapi.security import OAuth2PasswordRequestForm\n","sourceCodeStart":198,"sourceCodeEnd":234,"githubUrl":"https://github.com/affaan-m/ECC/blob/d8409a4b0813771235555e32e3d8046a73988bfa/skills/fastapi-patterns/SKILL.md#L198-L234","documentation":"Illustrative FastAPI dependency from the fastapi-patterns skill: get_current_active_user wraps get_current_user and rejects a successfully authenticated but deactivated account (is_active false) before route code runs.","triggerScenarios":"Thrown at skills/fastapi-patterns/SKILL.md:216 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Return 403 with a 'inactive account' detail so clients can prompt reactivation","Audit inactive users periodically and expire their tokens","Combine with token expiry so reactivation requires re-login"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"d8409a4b0813771235555e32e3d8046a73988bfa","analyzedAt":"2026-08-26T12:15:34.022Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}