diff --git a/nonce.py b/nonce.py index 3f3062f..2113402 100644 --- a/nonce.py +++ b/nonce.py @@ -1,109 +1,109 @@ -from flask import * -import secrets, hashlib -from model.models import * -import json - -app = Blueprint('nounce', __name__) - -SID = 'SID' -nonces = {} -authSessions = {} -users = {} - -def loadUsers(path): - global users - with open(path) as json_file: - users = json.load(json_file) - -@app.route('/nonce', methods=['GET']) -def nounce(): - n = tryGetSessionNonce() - if n == None or n.expired(): - n = generateSessionNonce() - n.bump() - return jsonify(n.__dict__),201 - -@app.route('/login', methods=['POST']) -def login(): - if isLoggedIn(): - return 'already logged in', 400 - - n = tryGetSessionNonce() - if n == None: - return 'no nonce was generated', 400 - if n.expired(): - clearSessionNonce() - return 'nonce expired', 408 - - user = request.form['user'] - cnonce = request.form['cnonce'] - pwdhash = request.form['pwdhash'] - - pwdHashed_sha256 = '' - if user in users: - pwdHashed_sha256 = users[user] - else: - abort(403) - - hash = generateHash(pwdHashed_sha256, cnonce, n.token) - if hash == pwdhash: - s = generateAuthSession(user) - return jsonify(s.__dict__),201 - else: - abort(403) - -@app.route('/check-login', methods=['GET']) -def checkLogin(): - if isLoggedIn(): - asession = authSessions[session[SID]] - asession.bumpExpiration() - return jsonify(asession.__dict__) - else: - return abort(403) - -@app.route('/login-page', methods=['GET']) -def loginPage(): - return render_template('login-page.html') - -def isLoggedIn(): - if SID in session and session[SID] in authSessions: - return not(authSessions[session[SID]].expired()) - return False - -def generateAuthSession(username): - asession = AuthSession(username) - authSessions[session[SID]] = asession - return asession - -def getAuthSession(): - if not SID in session: - return None - if not session[SID]: - return None - return authSessions[session[SID]] - -def clearSessionNonce(): - if not SID in session: - return - if not session[SID] in nonces: - return - del nonces[session[SID]] - -def tryGetSessionNonce(): - if not SID in session: - return None - if not session[SID] in nonces: - return None - return nonces[session[SID]] - -def generateSessionNonce(): - n = Nounce() - session[SID] = secrets.token_urlsafe() - nonces[session[SID]] = n - return n - -def generateHash(pwdsha256,cnonce,nonce): - all = pwdsha256+cnonce+nonce - sha256 = hashlib.sha256( ) - sha256.update( all.encode('utf8') ) - return sha256.hexdigest() +from flask import * +import secrets, hashlib +from model.models import * +import json + +app = Blueprint('nounce', __name__) + +SID = 'SID' +nonces = {} +authSessions = {} +users = {} + +def loadUsers(path): + global users + with open(path) as json_file: + users = json.load(json_file) + +@app.route('/nonce', methods=['GET']) +def nounce(): + n = tryGetSessionNonce() + if n == None or n.expired(): + n = generateSessionNonce() + n.bump() + return jsonify(n.__dict__),201 + +@app.route('/login', methods=['POST']) +def login(): + if isLoggedIn(): + return 'already logged in', 400 + + n = tryGetSessionNonce() + if n == None: + return 'no nonce was generated', 400 + if n.expired(): + clearSessionNonce() + return 'nonce expired', 408 + + user = request.form['user'] + cnonce = request.form['cnonce'] + pwdhash = request.form['pwdhash'] + + pwdHashed_sha256 = '' + if user in users: + pwdHashed_sha256 = users[user] + else: + abort(403) + + hash = generateHash(pwdHashed_sha256, cnonce, n.token) + if hash == pwdhash: + s = generateAuthSession(user) + return jsonify(s.__dict__),201 + else: + abort(403) + +@app.route('/check-login', methods=['GET']) +def checkLogin(): + if isLoggedIn(): + asession = authSessions[session[SID]] + asession.bumpExpiration() + return jsonify(asession.__dict__) + else: + return abort(403) + +@app.route('/login-page', methods=['GET']) +def loginPage(): + return render_template('login-page.html') + +def isLoggedIn(): + if SID in session and session[SID] in authSessions: + return not(authSessions[session[SID]].expired()) + return False + +def generateAuthSession(username): + asession = AuthSession(username) + authSessions[session[SID]] = asession + return asession + +def getAuthSession(): + if not SID in session: + return None + if not session[SID]: + return None + return authSessions[session[SID]] + +def clearSessionNonce(): + if not SID in session: + return + if not session[SID] in nonces: + return + del nonces[session[SID]] + +def tryGetSessionNonce(): + if not SID in session: + return None + if not session[SID] in nonces: + return None + return nonces[session[SID]] + +def generateSessionNonce(): + n = Nounce() + session[SID] = secrets.token_urlsafe() + nonces[session[SID]] = n + return n + +def generateHash(pwdsha256,cnonce,nonce): + all = pwdsha256+cnonce+nonce + sha256 = hashlib.sha256( ) + sha256.update( all.encode('utf8') ) + return sha256.hexdigest() diff --git a/simple_auth_service.py b/simple_auth_service.py index f0cc959..5c46ea8 100644 --- a/simple_auth_service.py +++ b/simple_auth_service.py @@ -15,5 +15,5 @@ def home(): nonce.loadUsers( os.path.join('data','userlist.json') ) if __name__ == '__main__': - app.run( host='0.0.0.0', port=7070) + app.run( port=7070)