version 2.13.1
This commit is contained in:
+20
-20
@@ -1426,7 +1426,7 @@ class Auth(object):
|
||||
csrf_prevention=True, propagate_extension=None,
|
||||
url_index=None):
|
||||
|
||||
## next two lines for backward compatibility
|
||||
## next two lines for backward compatibility
|
||||
if not db and environment and isinstance(environment, DAL):
|
||||
db = environment
|
||||
self.db = db
|
||||
@@ -1544,7 +1544,7 @@ class Auth(object):
|
||||
self.define_signature()
|
||||
else:
|
||||
self.signature = None
|
||||
|
||||
|
||||
def get_vars_next(self):
|
||||
next = current.request.vars._next
|
||||
if isinstance(next, (list, tuple)):
|
||||
@@ -1554,7 +1554,7 @@ class Auth(object):
|
||||
# _next variable in the request.
|
||||
items = next.split('/')
|
||||
if '//' in next and items[2] != current.request.env.http_host:
|
||||
next = None
|
||||
next = None
|
||||
return next
|
||||
|
||||
def _get_user_id(self):
|
||||
@@ -1611,7 +1611,7 @@ class Auth(object):
|
||||
'retrieve_username', 'retrieve_password',
|
||||
'reset_password', 'request_reset_password',
|
||||
'change_password', 'profile', 'groups',
|
||||
'impersonate', 'not_authorized', 'confirm_registration',
|
||||
'impersonate', 'not_authorized', 'confirm_registration',
|
||||
'bulk_register','manage_tokens'):
|
||||
if len(request.args) >= 2 and args[0] == 'impersonate':
|
||||
return getattr(self, args[0])(request.args[1])
|
||||
@@ -2373,7 +2373,7 @@ class Auth(object):
|
||||
and a raw password.
|
||||
"""
|
||||
settings = self._get_login_settings()
|
||||
# users can register_bare even if no password is provided,
|
||||
# users can register_bare even if no password is provided,
|
||||
# in this case they will have to reset their password to login
|
||||
if fields.get(settings.passfield):
|
||||
fields[settings.passfield] = \
|
||||
@@ -2381,7 +2381,7 @@ class Auth(object):
|
||||
if not fields.get(settings.userfield):
|
||||
raise ValueError('register_bare: ' +
|
||||
'userfield not provided or invalid')
|
||||
user = self.get_or_create_user(fields, login=False, get=False,
|
||||
user = self.get_or_create_user(fields, login=False, get=False,
|
||||
update_fields=self.settings.update_fields)
|
||||
if not user:
|
||||
# get or create did not create a user (it ignores duplicate records)
|
||||
@@ -2732,7 +2732,7 @@ class Auth(object):
|
||||
# username and password at the first challenge).
|
||||
# Check if this user is signed up for two-factor authentication
|
||||
# If auth.settings.auth_two_factor_enabled it will enable two factor
|
||||
# for all the app. Another way to anble two factor is that the user
|
||||
# for all the app. Another way to anble two factor is that the user
|
||||
# must be part of a group that is called auth.settings.two_factor_authentication_group
|
||||
if user and self.settings.auth_two_factor_enabled == True:
|
||||
session.auth_two_factor_enabled = True
|
||||
@@ -2763,7 +2763,7 @@ class Auth(object):
|
||||
session.auth_two_factor_tries_left = self.settings.auth_two_factor_tries_left
|
||||
# Set the way we generate the code or we send the code. For example using SMS...
|
||||
two_factor_methods = self.settings.two_factor_methods
|
||||
|
||||
|
||||
if two_factor_methods == []:
|
||||
# TODO: Add some error checking to handle cases where email cannot be sent
|
||||
self.settings.mailer.send(
|
||||
@@ -2780,19 +2780,19 @@ class Auth(object):
|
||||
pass
|
||||
else:
|
||||
break
|
||||
|
||||
|
||||
if form.accepts(request, session if self.csrf_prevention else None,
|
||||
formname='login', dbio=False,
|
||||
onvalidation=onvalidation,
|
||||
hideerror=settings.hideerror):
|
||||
accepted_form = True
|
||||
|
||||
|
||||
accepted_form = True
|
||||
|
||||
|
||||
'''
|
||||
The lists is executed after form validation for each of the corresponding action.
|
||||
For example, in your model:
|
||||
|
||||
|
||||
In your models copy and paste:
|
||||
|
||||
#Before define tables, we add some extra field to auth_user
|
||||
@@ -2802,7 +2802,7 @@ class Auth(object):
|
||||
|
||||
OFFSET = 60 #Be sure is the same in your OTP Client
|
||||
|
||||
#Set session.auth_two_factor to None. Because the code is generated by external app.
|
||||
#Set session.auth_two_factor to None. Because the code is generated by external app.
|
||||
# This will avoid to use the default setting and send a code by email.
|
||||
def _set_two_factor(user, auth_two_factor):
|
||||
return None
|
||||
@@ -2823,10 +2823,10 @@ class Auth(object):
|
||||
auth.messages.two_factor_comment = "Verify your OTP Client for the code."
|
||||
auth.settings.two_factor_methods = [lambda user, auth_two_factor: _set_two_factor(user, auth_two_factor)]
|
||||
auth.settings.two_factor_onvalidation = [lambda user, otp: verify_otp(user, otp)]
|
||||
|
||||
|
||||
'''
|
||||
if self.settings.two_factor_onvalidation != []:
|
||||
|
||||
|
||||
for two_factor_onvalidation in self.settings.two_factor_onvalidation:
|
||||
try:
|
||||
session.auth_two_factor = two_factor_onvalidation(session.auth_two_factor_user, form.vars['authentication_code'])
|
||||
@@ -2834,7 +2834,7 @@ class Auth(object):
|
||||
pass
|
||||
else:
|
||||
break
|
||||
|
||||
|
||||
if form.vars['authentication_code'] == str(session.auth_two_factor):
|
||||
# Handle the case when the two-factor form has been successfully validated
|
||||
# and the user was previously stored (the current user should be None because
|
||||
@@ -2994,7 +2994,7 @@ class Auth(object):
|
||||
except:
|
||||
pass
|
||||
|
||||
if self.settings.register_verify_password:
|
||||
if self.settings.register_verify_password:
|
||||
if self.settings.register_fields is None:
|
||||
self.settings.register_fields = [f.name for f in table_user if f.writable]
|
||||
k = self.settings.register_fields.index("password")
|
||||
@@ -3005,7 +3005,7 @@ class Auth(object):
|
||||
error_message=self.messages.mismatched_password),
|
||||
label=current.T("Confirm Password"))]
|
||||
else:
|
||||
extra_fields = []
|
||||
extra_fields = []
|
||||
form = SQLFORM(table_user,
|
||||
fields=self.settings.register_fields,
|
||||
hidden=dict(_next=next),
|
||||
@@ -3382,7 +3382,7 @@ class Auth(object):
|
||||
|
||||
if form.process().accepted:
|
||||
emails = re.compile('[^\s\'"@<>,;:]+\@[^\s\'"@<>,;:]+').findall(form.vars.emails)
|
||||
# send the invitations
|
||||
# send the invitations
|
||||
emails_sent = []
|
||||
emails_fail = []
|
||||
emails_exist = []
|
||||
@@ -3403,7 +3403,7 @@ class Auth(object):
|
||||
|
||||
def manage_tokens(self):
|
||||
if not self.user:
|
||||
redirect(self.settings.login_url)
|
||||
redirect(self.settings.login_url)
|
||||
table_token =self.table_token()
|
||||
table_token.user_id.writable = False
|
||||
table_token.user_id.default = self.user.id
|
||||
|
||||
Reference in New Issue
Block a user