# Python authentication flow proof bundle

This is a small, auditable implementation of registration, login, logout,
bcrypt password hashing, opaque server-side sessions, optional HS256 JWTs, and
CSRF protection. The HTTP adapter exposes `POST /register`, `POST /login`, and
`POST /logout` as JSON endpoints.

The sample uses in-memory stores so it is deterministic and safe to inspect.
For production, replace them with a database, use a secret manager for the JWT
key, set secure/HttpOnly/SameSite cookies at the edge, add rate limiting, and
use TLS. Passwords are never logged or returned. Logout requires the session's
CSRF token; authentication failures use a generic message.

## Run

```bash
python -m pip install -r requirements.txt
python auth_http.py
```

## Verify

```bash
python -m unittest -v test_auth_core.py
sha256sum -c SHA256SUMS
```

The nine tests cover registration, duplicate and password validation, login,
session revocation/expiry, CSRF enforcement, JWT verification, and tamper
detection. No wallet, private key, API credential, or payment is involved.
