diff options
| author | LV-426 <lv-426@taproot.org.il> | 2015-02-04 02:06:50 +0200 |
|---|---|---|
| committer | LV-426 <lv-426@taproot.org.il> | 2015-02-04 02:06:50 +0200 |
| commit | a78203ec7ab97015462a4d6ee5819e2c96ae1115 (patch) | |
| tree | afe4206d0f39c33eb7922ed467cbcae3fe33f581 /src | |
| parent | 65da07db081c4192407d3fa7a1899e81d0c171ad (diff) | |
crypt_util: refactor validate_login(), mv to User_DB
Diffstat (limited to 'src')
| -rw-r--r-- | src/server/crypt_util.py | 21 | ||||
| -rw-r--r-- | src/server/rz_user_db.py | 9 |
2 files changed, 10 insertions, 20 deletions
diff --git a/src/server/crypt_util.py b/src/server/crypt_util.py index a3b2582d..057ed4bc 100644 --- a/src/server/crypt_util.py +++ b/src/server/crypt_util.py @@ -1,7 +1,5 @@ -import hashlib, uuid +import hashlib import logging -import pickle - log = logging.getLogger('rhizi') @@ -9,20 +7,3 @@ def hash_pw(pw_str, salt_str): salt = hashlib.sha512(salt_str).hexdigest() ret = hashlib.sha512(pw_str + salt).hexdigest() return ret - -def validate_login(config, u, p): - htpasswd_path = config.htpasswd_path - - salt = config.secret_key - - with open(htpasswd_path) as f: - pw_db = pickle.load(f) - - existing_pw_hash = pw_db.get(u) - if None == existing_pw_hash: - raise Exception('Not authorized') - - if hash_pw(p, salt) != existing_pw_hash: - raise Exception('Not authorized') - - diff --git a/src/server/rz_user_db.py b/src/server/rz_user_db.py index ebca5465..31ec1357 100644 --- a/src/server/rz_user_db.py +++ b/src/server/rz_user_db.py @@ -127,5 +127,14 @@ class User_DB(object): u = self.persistent_data_store[uid] return role in u.role_set + def validate_login(self, email_address, pw_hash): + _, u = self.__lookup_user__by_email_address(email_address) + existing_pw_hash = u.pw_hash + + assert None != existing_pw_hash, 'missing pw_hash for existing user' + + if pw_hash != existing_pw_hash: + raise Exception('Not authorized') + def shutdown(self): self.persistent_data_store.close() |
