diff options
| author | Alon Levy <alon@pobox.com> | 2014-12-16 17:14:32 +0200 |
|---|---|---|
| committer | Alon Levy <alon@pobox.com> | 2014-12-16 17:14:32 +0200 |
| commit | c7d026b1d504323a8c61d51b726e5e8d2337fc4b (patch) | |
| tree | 75607d07c90beb8024e34afd2bab3503dcaccda4 /src-py/crypt_util.py | |
| parent | dff765d765085fe2ee172abc606f4f8b25a39c27 (diff) | |
| parent | 38078c537f642806e4849dc99c07d679f816fe23 (diff) | |
Merging rhizi-server into rhizi, back to a single repo
Merge remote-tracking branch 'old-server/master' into wip/map-nodes-by-id_minimize-name-use
Diffstat (limited to 'src-py/crypt_util.py')
| -rw-r--r-- | src-py/crypt_util.py | 46 |
1 files changed, 46 insertions, 0 deletions
diff --git a/src-py/crypt_util.py b/src-py/crypt_util.py new file mode 100644 index 00000000..464fac94 --- /dev/null +++ b/src-py/crypt_util.py @@ -0,0 +1,46 @@ +import pickle +import hashlib, uuid +import os +import logging + +log = logging.getLogger('rhizi') + +def add_user_login(config, u, p): + htpasswd_path = config.htpasswd_path + + if False == os.path.exists(htpasswd_path): + with open(htpasswd_path, 'wb') as f: + pickle.dump({}, f) + + with open(htpasswd_path, 'rb') as f: + data = f.read() + pw_db = pickle.loads(data) + + with open(htpasswd_path, 'wb') as f: + salt = config.secret_key + pw_db[u] = hash_pw(str(p), salt) + pickle.dump(pw_db, f) + + log.info('htpasswd db: added entry: user: %s, pw: %s...' % (u, pw_db[u][:5])) + +def hash_pw(pw_str, salt_str): + salt = hashlib.sha512(salt_str).hexdigest() + ret = hashlib.sha512(pw_str + salt).hexdigest() + return ret + +def validate_login(config, u, p): + htpasswd_path = config.htpasswd_path + + salt = config.secret_key + + with open(htpasswd_path) as f: + pw_db = pickle.load(f) + + existing_pw_hash = pw_db.get(u) + if None == existing_pw_hash: + raise Exception('Not autorhized') + + if hash_pw(p, salt) != existing_pw_hash: + raise Exception('Not autorhized') + + |
