You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
109 lines
2.6 KiB
109 lines
2.6 KiB
from flask import *
|
|
import secrets, hashlib
|
|
from model.models import *
|
|
import json
|
|
|
|
app = Blueprint('nounce', __name__)
|
|
|
|
SID = 'SID'
|
|
nonces = {}
|
|
authSessions = {}
|
|
users = {}
|
|
|
|
def loadUsers(path):
|
|
global users
|
|
with open(path) as json_file:
|
|
users = json.load(json_file)
|
|
|
|
@app.route('/nonce', methods=['GET'])
|
|
def nounce():
|
|
n = tryGetSessionNonce()
|
|
if n == None or n.expired():
|
|
n = generateSessionNonce()
|
|
n.bump()
|
|
return jsonify(n.__dict__),201
|
|
|
|
@app.route('/login', methods=['POST'])
|
|
def login():
|
|
if isLoggedIn():
|
|
return 'already logged in', 400
|
|
|
|
n = tryGetSessionNonce()
|
|
if n == None:
|
|
return 'no nonce was generated', 400
|
|
if n.expired():
|
|
clearSessionNonce()
|
|
return 'nonce expired', 408
|
|
|
|
user = request.form['user']
|
|
cnonce = request.form['cnonce']
|
|
pwdhash = request.form['pwdhash']
|
|
|
|
pwdHashed_sha256 = ''
|
|
if user in users:
|
|
pwdHashed_sha256 = users[user]
|
|
else:
|
|
abort(403)
|
|
|
|
hash = generateHash(pwdHashed_sha256, cnonce, n.token)
|
|
if hash == pwdhash:
|
|
s = generateAuthSession(user)
|
|
return jsonify(s.__dict__),201
|
|
else:
|
|
abort(403)
|
|
|
|
@app.route('/check-login', methods=['GET'])
|
|
def checkLogin():
|
|
if isLoggedIn():
|
|
asession = authSessions[session[SID]]
|
|
asession.bumpExpiration()
|
|
return jsonify(asession.__dict__)
|
|
else:
|
|
return abort(403)
|
|
|
|
@app.route('/login-page', methods=['GET'])
|
|
def loginPage():
|
|
return render_template('login-page.html')
|
|
|
|
def isLoggedIn():
|
|
if SID in session and session[SID] in authSessions:
|
|
return not(authSessions[session[SID]].expired())
|
|
return False
|
|
|
|
def generateAuthSession(username):
|
|
asession = AuthSession(username)
|
|
authSessions[session[SID]] = asession
|
|
return asession
|
|
|
|
def getAuthSession():
|
|
if not SID in session:
|
|
return None
|
|
if not session[SID]:
|
|
return None
|
|
return authSessions[session[SID]]
|
|
|
|
def clearSessionNonce():
|
|
if not SID in session:
|
|
return
|
|
if not session[SID] in nonces:
|
|
return
|
|
del nonces[session[SID]]
|
|
|
|
def tryGetSessionNonce():
|
|
if not SID in session:
|
|
return None
|
|
if not session[SID] in nonces:
|
|
return None
|
|
return nonces[session[SID]]
|
|
|
|
def generateSessionNonce():
|
|
n = Nounce()
|
|
session[SID] = secrets.token_urlsafe()
|
|
nonces[session[SID]] = n
|
|
return n
|
|
|
|
def generateHash(pwdsha256,cnonce,nonce):
|
|
all = pwdsha256+cnonce+nonce
|
|
sha256 = hashlib.sha256( )
|
|
sha256.update( all.encode('utf8') )
|
|
return sha256.hexdigest()
|
|
|