parent
09a2c47edc
commit
e8c8c84f9e
@ -1,109 +1,109 @@ |
|||||||
from flask import * |
from flask import * |
||||||
import secrets, hashlib |
import secrets, hashlib |
||||||
from model.models import * |
from model.models import * |
||||||
import json |
import json |
||||||
|
|
||||||
app = Blueprint('nounce', __name__) |
app = Blueprint('nounce', __name__) |
||||||
|
|
||||||
SID = 'SID' |
SID = 'SID' |
||||||
nonces = {} |
nonces = {} |
||||||
authSessions = {} |
authSessions = {} |
||||||
users = {} |
users = {} |
||||||
|
|
||||||
def loadUsers(path): |
def loadUsers(path): |
||||||
global users |
global users |
||||||
with open(path) as json_file: |
with open(path) as json_file: |
||||||
users = json.load(json_file) |
users = json.load(json_file) |
||||||
|
|
||||||
@app.route('/nonce', methods=['GET']) |
@app.route('/nonce', methods=['GET']) |
||||||
def nounce(): |
def nounce(): |
||||||
n = tryGetSessionNonce() |
n = tryGetSessionNonce() |
||||||
if n == None or n.expired(): |
if n == None or n.expired(): |
||||||
n = generateSessionNonce() |
n = generateSessionNonce() |
||||||
n.bump() |
n.bump() |
||||||
return jsonify(n.__dict__),201 |
return jsonify(n.__dict__),201 |
||||||
|
|
||||||
@app.route('/login', methods=['POST']) |
@app.route('/login', methods=['POST']) |
||||||
def login(): |
def login(): |
||||||
if isLoggedIn(): |
if isLoggedIn(): |
||||||
return 'already logged in', 400 |
return 'already logged in', 400 |
||||||
|
|
||||||
n = tryGetSessionNonce() |
n = tryGetSessionNonce() |
||||||
if n == None: |
if n == None: |
||||||
return 'no nonce was generated', 400 |
return 'no nonce was generated', 400 |
||||||
if n.expired(): |
if n.expired(): |
||||||
clearSessionNonce() |
clearSessionNonce() |
||||||
return 'nonce expired', 408 |
return 'nonce expired', 408 |
||||||
|
|
||||||
user = request.form['user'] |
user = request.form['user'] |
||||||
cnonce = request.form['cnonce'] |
cnonce = request.form['cnonce'] |
||||||
pwdhash = request.form['pwdhash'] |
pwdhash = request.form['pwdhash'] |
||||||
|
|
||||||
pwdHashed_sha256 = '' |
pwdHashed_sha256 = '' |
||||||
if user in users: |
if user in users: |
||||||
pwdHashed_sha256 = users[user] |
pwdHashed_sha256 = users[user] |
||||||
else: |
else: |
||||||
abort(403) |
abort(403) |
||||||
|
|
||||||
hash = generateHash(pwdHashed_sha256, cnonce, n.token) |
hash = generateHash(pwdHashed_sha256, cnonce, n.token) |
||||||
if hash == pwdhash: |
if hash == pwdhash: |
||||||
s = generateAuthSession(user) |
s = generateAuthSession(user) |
||||||
return jsonify(s.__dict__),201 |
return jsonify(s.__dict__),201 |
||||||
else: |
else: |
||||||
abort(403) |
abort(403) |
||||||
|
|
||||||
@app.route('/check-login', methods=['GET']) |
@app.route('/check-login', methods=['GET']) |
||||||
def checkLogin(): |
def checkLogin(): |
||||||
if isLoggedIn(): |
if isLoggedIn(): |
||||||
asession = authSessions[session[SID]] |
asession = authSessions[session[SID]] |
||||||
asession.bumpExpiration() |
asession.bumpExpiration() |
||||||
return jsonify(asession.__dict__) |
return jsonify(asession.__dict__) |
||||||
else: |
else: |
||||||
return abort(403) |
return abort(403) |
||||||
|
|
||||||
@app.route('/login-page', methods=['GET']) |
@app.route('/login-page', methods=['GET']) |
||||||
def loginPage(): |
def loginPage(): |
||||||
return render_template('login-page.html') |
return render_template('login-page.html') |
||||||
|
|
||||||
def isLoggedIn(): |
def isLoggedIn(): |
||||||
if SID in session and session[SID] in authSessions: |
if SID in session and session[SID] in authSessions: |
||||||
return not(authSessions[session[SID]].expired()) |
return not(authSessions[session[SID]].expired()) |
||||||
return False |
return False |
||||||
|
|
||||||
def generateAuthSession(username): |
def generateAuthSession(username): |
||||||
asession = AuthSession(username) |
asession = AuthSession(username) |
||||||
authSessions[session[SID]] = asession |
authSessions[session[SID]] = asession |
||||||
return asession |
return asession |
||||||
|
|
||||||
def getAuthSession(): |
def getAuthSession(): |
||||||
if not SID in session: |
if not SID in session: |
||||||
return None |
return None |
||||||
if not session[SID]: |
if not session[SID]: |
||||||
return None |
return None |
||||||
return authSessions[session[SID]] |
return authSessions[session[SID]] |
||||||
|
|
||||||
def clearSessionNonce(): |
def clearSessionNonce(): |
||||||
if not SID in session: |
if not SID in session: |
||||||
return |
return |
||||||
if not session[SID] in nonces: |
if not session[SID] in nonces: |
||||||
return |
return |
||||||
del nonces[session[SID]] |
del nonces[session[SID]] |
||||||
|
|
||||||
def tryGetSessionNonce(): |
def tryGetSessionNonce(): |
||||||
if not SID in session: |
if not SID in session: |
||||||
return None |
return None |
||||||
if not session[SID] in nonces: |
if not session[SID] in nonces: |
||||||
return None |
return None |
||||||
return nonces[session[SID]] |
return nonces[session[SID]] |
||||||
|
|
||||||
def generateSessionNonce(): |
def generateSessionNonce(): |
||||||
n = Nounce() |
n = Nounce() |
||||||
session[SID] = secrets.token_urlsafe() |
session[SID] = secrets.token_urlsafe() |
||||||
nonces[session[SID]] = n |
nonces[session[SID]] = n |
||||||
return n |
return n |
||||||
|
|
||||||
def generateHash(pwdsha256,cnonce,nonce): |
def generateHash(pwdsha256,cnonce,nonce): |
||||||
all = pwdsha256+cnonce+nonce |
all = pwdsha256+cnonce+nonce |
||||||
sha256 = hashlib.sha256( ) |
sha256 = hashlib.sha256( ) |
||||||
sha256.update( all.encode('utf8') ) |
sha256.update( all.encode('utf8') ) |
||||||
return sha256.hexdigest() |
return sha256.hexdigest() |
||||||
|
|||||||
Loading…
Reference in new issue