diff options
| author | Alon Levy <alon@pobox.com> | 2014-12-16 17:37:42 +0200 |
|---|---|---|
| committer | Alon Levy <alon@pobox.com> | 2014-12-16 17:37:42 +0200 |
| commit | ade19de410e0a789a921ec1666b278b2a64176d6 (patch) | |
| tree | c4c54b106de93609ca7bb70a20fd4be696715dbe /src/server/crypt_util.py | |
| parent | c7d026b1d504323a8c61d51b726e5e8d2337fc4b (diff) | |
moving files around after repository merger
Diffstat (limited to 'src/server/crypt_util.py')
| -rw-r--r-- | src/server/crypt_util.py | 46 |
1 files changed, 46 insertions, 0 deletions
diff --git a/src/server/crypt_util.py b/src/server/crypt_util.py new file mode 100644 index 00000000..464fac94 --- /dev/null +++ b/src/server/crypt_util.py @@ -0,0 +1,46 @@ +import pickle +import hashlib, uuid +import os +import logging + +log = logging.getLogger('rhizi') + +def add_user_login(config, u, p): + htpasswd_path = config.htpasswd_path + + if False == os.path.exists(htpasswd_path): + with open(htpasswd_path, 'wb') as f: + pickle.dump({}, f) + + with open(htpasswd_path, 'rb') as f: + data = f.read() + pw_db = pickle.loads(data) + + with open(htpasswd_path, 'wb') as f: + salt = config.secret_key + pw_db[u] = hash_pw(str(p), salt) + pickle.dump(pw_db, f) + + log.info('htpasswd db: added entry: user: %s, pw: %s...' % (u, pw_db[u][:5])) + +def hash_pw(pw_str, salt_str): + salt = hashlib.sha512(salt_str).hexdigest() + ret = hashlib.sha512(pw_str + salt).hexdigest() + return ret + +def validate_login(config, u, p): + htpasswd_path = config.htpasswd_path + + salt = config.secret_key + + with open(htpasswd_path) as f: + pw_db = pickle.load(f) + + existing_pw_hash = pw_db.get(u) + if None == existing_pw_hash: + raise Exception('Not autorhized') + + if hash_pw(p, salt) != existing_pw_hash: + raise Exception('Not autorhized') + + |
