version 2.13.1

This commit is contained in:
mdipierro
2015-12-17 21:19:08 -06:00
parent 1636528a0f
commit 22c89d8dcc
13 changed files with 98 additions and 88 deletions
+20 -20
View File
@@ -1426,7 +1426,7 @@ class Auth(object):
csrf_prevention=True, propagate_extension=None,
url_index=None):
## next two lines for backward compatibility
## next two lines for backward compatibility
if not db and environment and isinstance(environment, DAL):
db = environment
self.db = db
@@ -1544,7 +1544,7 @@ class Auth(object):
self.define_signature()
else:
self.signature = None
def get_vars_next(self):
next = current.request.vars._next
if isinstance(next, (list, tuple)):
@@ -1554,7 +1554,7 @@ class Auth(object):
# _next variable in the request.
items = next.split('/')
if '//' in next and items[2] != current.request.env.http_host:
next = None
next = None
return next
def _get_user_id(self):
@@ -1611,7 +1611,7 @@ class Auth(object):
'retrieve_username', 'retrieve_password',
'reset_password', 'request_reset_password',
'change_password', 'profile', 'groups',
'impersonate', 'not_authorized', 'confirm_registration',
'impersonate', 'not_authorized', 'confirm_registration',
'bulk_register','manage_tokens'):
if len(request.args) >= 2 and args[0] == 'impersonate':
return getattr(self, args[0])(request.args[1])
@@ -2373,7 +2373,7 @@ class Auth(object):
and a raw password.
"""
settings = self._get_login_settings()
# users can register_bare even if no password is provided,
# users can register_bare even if no password is provided,
# in this case they will have to reset their password to login
if fields.get(settings.passfield):
fields[settings.passfield] = \
@@ -2381,7 +2381,7 @@ class Auth(object):
if not fields.get(settings.userfield):
raise ValueError('register_bare: ' +
'userfield not provided or invalid')
user = self.get_or_create_user(fields, login=False, get=False,
user = self.get_or_create_user(fields, login=False, get=False,
update_fields=self.settings.update_fields)
if not user:
# get or create did not create a user (it ignores duplicate records)
@@ -2732,7 +2732,7 @@ class Auth(object):
# username and password at the first challenge).
# Check if this user is signed up for two-factor authentication
# If auth.settings.auth_two_factor_enabled it will enable two factor
# for all the app. Another way to anble two factor is that the user
# for all the app. Another way to anble two factor is that the user
# must be part of a group that is called auth.settings.two_factor_authentication_group
if user and self.settings.auth_two_factor_enabled == True:
session.auth_two_factor_enabled = True
@@ -2763,7 +2763,7 @@ class Auth(object):
session.auth_two_factor_tries_left = self.settings.auth_two_factor_tries_left
# Set the way we generate the code or we send the code. For example using SMS...
two_factor_methods = self.settings.two_factor_methods
if two_factor_methods == []:
# TODO: Add some error checking to handle cases where email cannot be sent
self.settings.mailer.send(
@@ -2780,19 +2780,19 @@ class Auth(object):
pass
else:
break
if form.accepts(request, session if self.csrf_prevention else None,
formname='login', dbio=False,
onvalidation=onvalidation,
hideerror=settings.hideerror):
accepted_form = True
accepted_form = True
'''
The lists is executed after form validation for each of the corresponding action.
For example, in your model:
In your models copy and paste:
#Before define tables, we add some extra field to auth_user
@@ -2802,7 +2802,7 @@ class Auth(object):
OFFSET = 60 #Be sure is the same in your OTP Client
#Set session.auth_two_factor to None. Because the code is generated by external app.
#Set session.auth_two_factor to None. Because the code is generated by external app.
# This will avoid to use the default setting and send a code by email.
def _set_two_factor(user, auth_two_factor):
return None
@@ -2823,10 +2823,10 @@ class Auth(object):
auth.messages.two_factor_comment = "Verify your OTP Client for the code."
auth.settings.two_factor_methods = [lambda user, auth_two_factor: _set_two_factor(user, auth_two_factor)]
auth.settings.two_factor_onvalidation = [lambda user, otp: verify_otp(user, otp)]
'''
if self.settings.two_factor_onvalidation != []:
for two_factor_onvalidation in self.settings.two_factor_onvalidation:
try:
session.auth_two_factor = two_factor_onvalidation(session.auth_two_factor_user, form.vars['authentication_code'])
@@ -2834,7 +2834,7 @@ class Auth(object):
pass
else:
break
if form.vars['authentication_code'] == str(session.auth_two_factor):
# Handle the case when the two-factor form has been successfully validated
# and the user was previously stored (the current user should be None because
@@ -2994,7 +2994,7 @@ class Auth(object):
except:
pass
if self.settings.register_verify_password:
if self.settings.register_verify_password:
if self.settings.register_fields is None:
self.settings.register_fields = [f.name for f in table_user if f.writable]
k = self.settings.register_fields.index("password")
@@ -3005,7 +3005,7 @@ class Auth(object):
error_message=self.messages.mismatched_password),
label=current.T("Confirm Password"))]
else:
extra_fields = []
extra_fields = []
form = SQLFORM(table_user,
fields=self.settings.register_fields,
hidden=dict(_next=next),
@@ -3382,7 +3382,7 @@ class Auth(object):
if form.process().accepted:
emails = re.compile('[^\s\'"@<>,;:]+\@[^\s\'"@<>,;:]+').findall(form.vars.emails)
# send the invitations
# send the invitations
emails_sent = []
emails_fail = []
emails_exist = []
@@ -3403,7 +3403,7 @@ class Auth(object):
def manage_tokens(self):
if not self.user:
redirect(self.settings.login_url)
redirect(self.settings.login_url)
table_token =self.table_token()
table_token.user_id.writable = False
table_token.user_id.default = self.user.id