parent
09a2c47edc
commit
e8c8c84f9e
@ -1,109 +1,109 @@ |
||||
from flask import * |
||||
import secrets, hashlib |
||||
from model.models import * |
||||
import json |
||||
|
||||
app = Blueprint('nounce', __name__) |
||||
|
||||
SID = 'SID' |
||||
nonces = {} |
||||
authSessions = {} |
||||
users = {} |
||||
|
||||
def loadUsers(path): |
||||
global users |
||||
with open(path) as json_file: |
||||
users = json.load(json_file) |
||||
|
||||
@app.route('/nonce', methods=['GET']) |
||||
def nounce(): |
||||
n = tryGetSessionNonce() |
||||
if n == None or n.expired(): |
||||
n = generateSessionNonce() |
||||
n.bump() |
||||
return jsonify(n.__dict__),201 |
||||
|
||||
@app.route('/login', methods=['POST']) |
||||
def login(): |
||||
if isLoggedIn(): |
||||
return 'already logged in', 400 |
||||
|
||||
n = tryGetSessionNonce() |
||||
if n == None: |
||||
return 'no nonce was generated', 400 |
||||
if n.expired(): |
||||
clearSessionNonce() |
||||
return 'nonce expired', 408 |
||||
|
||||
user = request.form['user'] |
||||
cnonce = request.form['cnonce'] |
||||
pwdhash = request.form['pwdhash'] |
||||
|
||||
pwdHashed_sha256 = '' |
||||
if user in users: |
||||
pwdHashed_sha256 = users[user] |
||||
else: |
||||
abort(403) |
||||
|
||||
hash = generateHash(pwdHashed_sha256, cnonce, n.token) |
||||
if hash == pwdhash: |
||||
s = generateAuthSession(user) |
||||
return jsonify(s.__dict__),201 |
||||
else: |
||||
abort(403) |
||||
|
||||
@app.route('/check-login', methods=['GET']) |
||||
def checkLogin(): |
||||
if isLoggedIn(): |
||||
asession = authSessions[session[SID]] |
||||
asession.bumpExpiration() |
||||
return jsonify(asession.__dict__) |
||||
else: |
||||
return abort(403) |
||||
|
||||
@app.route('/login-page', methods=['GET']) |
||||
def loginPage(): |
||||
return render_template('login-page.html') |
||||
|
||||
def isLoggedIn(): |
||||
if SID in session and session[SID] in authSessions: |
||||
return not(authSessions[session[SID]].expired()) |
||||
return False |
||||
|
||||
def generateAuthSession(username): |
||||
asession = AuthSession(username) |
||||
authSessions[session[SID]] = asession |
||||
return asession |
||||
|
||||
def getAuthSession(): |
||||
if not SID in session: |
||||
return None |
||||
if not session[SID]: |
||||
return None |
||||
return authSessions[session[SID]] |
||||
|
||||
def clearSessionNonce(): |
||||
if not SID in session: |
||||
return |
||||
if not session[SID] in nonces: |
||||
return |
||||
del nonces[session[SID]] |
||||
|
||||
def tryGetSessionNonce(): |
||||
if not SID in session: |
||||
return None |
||||
if not session[SID] in nonces: |
||||
return None |
||||
return nonces[session[SID]] |
||||
|
||||
def generateSessionNonce(): |
||||
n = Nounce() |
||||
session[SID] = secrets.token_urlsafe() |
||||
nonces[session[SID]] = n |
||||
return n |
||||
|
||||
def generateHash(pwdsha256,cnonce,nonce): |
||||
all = pwdsha256+cnonce+nonce |
||||
sha256 = hashlib.sha256( ) |
||||
sha256.update( all.encode('utf8') ) |
||||
return sha256.hexdigest() |
||||
from flask import * |
||||
import secrets, hashlib |
||||
from model.models import * |
||||
import json |
||||
|
||||
app = Blueprint('nounce', __name__) |
||||
|
||||
SID = 'SID' |
||||
nonces = {} |
||||
authSessions = {} |
||||
users = {} |
||||
|
||||
def loadUsers(path): |
||||
global users |
||||
with open(path) as json_file: |
||||
users = json.load(json_file) |
||||
|
||||
@app.route('/nonce', methods=['GET']) |
||||
def nounce(): |
||||
n = tryGetSessionNonce() |
||||
if n == None or n.expired(): |
||||
n = generateSessionNonce() |
||||
n.bump() |
||||
return jsonify(n.__dict__),201 |
||||
|
||||
@app.route('/login', methods=['POST']) |
||||
def login(): |
||||
if isLoggedIn(): |
||||
return 'already logged in', 400 |
||||
|
||||
n = tryGetSessionNonce() |
||||
if n == None: |
||||
return 'no nonce was generated', 400 |
||||
if n.expired(): |
||||
clearSessionNonce() |
||||
return 'nonce expired', 408 |
||||
|
||||
user = request.form['user'] |
||||
cnonce = request.form['cnonce'] |
||||
pwdhash = request.form['pwdhash'] |
||||
|
||||
pwdHashed_sha256 = '' |
||||
if user in users: |
||||
pwdHashed_sha256 = users[user] |
||||
else: |
||||
abort(403) |
||||
|
||||
hash = generateHash(pwdHashed_sha256, cnonce, n.token) |
||||
if hash == pwdhash: |
||||
s = generateAuthSession(user) |
||||
return jsonify(s.__dict__),201 |
||||
else: |
||||
abort(403) |
||||
|
||||
@app.route('/check-login', methods=['GET']) |
||||
def checkLogin(): |
||||
if isLoggedIn(): |
||||
asession = authSessions[session[SID]] |
||||
asession.bumpExpiration() |
||||
return jsonify(asession.__dict__) |
||||
else: |
||||
return abort(403) |
||||
|
||||
@app.route('/login-page', methods=['GET']) |
||||
def loginPage(): |
||||
return render_template('login-page.html') |
||||
|
||||
def isLoggedIn(): |
||||
if SID in session and session[SID] in authSessions: |
||||
return not(authSessions[session[SID]].expired()) |
||||
return False |
||||
|
||||
def generateAuthSession(username): |
||||
asession = AuthSession(username) |
||||
authSessions[session[SID]] = asession |
||||
return asession |
||||
|
||||
def getAuthSession(): |
||||
if not SID in session: |
||||
return None |
||||
if not session[SID]: |
||||
return None |
||||
return authSessions[session[SID]] |
||||
|
||||
def clearSessionNonce(): |
||||
if not SID in session: |
||||
return |
||||
if not session[SID] in nonces: |
||||
return |
||||
del nonces[session[SID]] |
||||
|
||||
def tryGetSessionNonce(): |
||||
if not SID in session: |
||||
return None |
||||
if not session[SID] in nonces: |
||||
return None |
||||
return nonces[session[SID]] |
||||
|
||||
def generateSessionNonce(): |
||||
n = Nounce() |
||||
session[SID] = secrets.token_urlsafe() |
||||
nonces[session[SID]] = n |
||||
return n |
||||
|
||||
def generateHash(pwdsha256,cnonce,nonce): |
||||
all = pwdsha256+cnonce+nonce |
||||
sha256 = hashlib.sha256( ) |
||||
sha256.update( all.encode('utf8') ) |
||||
return sha256.hexdigest() |
||||
|
||||
Loading…
Reference in new issue