fixed issue 1252, thanks Mark Weissen

This commit is contained in:
mdipierro
2013-01-08 08:58:30 -06:00
parent bd485d37c9
commit 30e32c07b9
2 changed files with 17 additions and 14 deletions
+1 -1
View File
@@ -1 +1 @@
Version 2.4.1-alpha.2+timestamp.2013.01.08.08.48.34 Version 2.4.1-alpha.2+timestamp.2013.01.08.08.57.51
+16 -13
View File
@@ -129,18 +129,21 @@ class OpenIDAuth(object):
def _define_alt_login_table(self): def _define_alt_login_table(self):
""" """
Define the OpenID login table. Define the OpenID login table.
Note: type is what I used for our project. We're going to support 'fackbook' and Note: oidtype is what I used for our project.
'plurk' alternate login methods. Otherwise it's always 'openid' and you We're going to support 'fackbook' and
'plurk' alternate login methods.
Otherwise it's always 'openid' and you
may not need it. This should be easy to changed. may not need it. This should be easy to changed.
(Just remove the field of "type" and remove the (Just remove the field of "type" and remove the
"and db.alt_logins.type == type_" in _find_matched_openid function) "and db.alt_logins.oidtype == type_"
in _find_matched_openid function)
""" """
db = self.db db = self.db
table = db.define_table( table = db.define_table(
self.table_alt_logins_name, self.table_alt_logins_name,
Field('username', length=512, default=''), Field('username', length=512, default=''),
Field('type', length=128, default='openid', readable=False), Field('oidtype', length=128, default='openid', readable=False),
Field('user', self.table_user, readable=False), Field('oiduser', self.table_user, readable=False),
) )
table.username.requires = IS_NOT_IN_DB(db, table.username) table.username.requires = IS_NOT_IN_DB(db, table.username)
self.table_alt_logins = table self.table_alt_logins = table
@@ -213,7 +216,7 @@ class OpenIDAuth(object):
# Get existed OpenID user # Get existed OpenID user
user = db( user = db(
self.table_user.id == alt_login.user).select().first() self.table_user.id == alt_login.oiduser).select().first()
if user: if user:
if current.session.w2popenid: if current.session.w2popenid:
del(current.session.w2popenid) del(current.session.w2popenid)
@@ -230,7 +233,7 @@ class OpenIDAuth(object):
Get the matched OpenID for given Get the matched OpenID for given
""" """
query = ( query = (
(db.alt_logins.username == oid) & (db.alt_logins.type == type_)) (db.alt_logins.username == oid) & (db.alt_logins.oidtype == type_))
alt_login = db(query).select().first() # Get the OpenID record alt_login = db(query).select().first() # Get the OpenID record
return alt_login return alt_login
@@ -239,7 +242,7 @@ class OpenIDAuth(object):
Associate the user logged in with given OpenID Associate the user logged in with given OpenID
""" """
# print "[DB] %s authenticated" % oid # print "[DB] %s authenticated" % oid
self.db.alt_logins.insert(username=oid, user=user.id) self.db.alt_logins.insert(username=oid, oiduser=user.id)
def _form_with_notification(self): def _form_with_notification(self):
""" """
@@ -400,7 +403,7 @@ width: 400px;
if 'delete_openid' in request.vars: if 'delete_openid' in request.vars:
self.remove_openid(request.vars.delete_openid) self.remove_openid(request.vars.delete_openid)
query = self.db.alt_logins.user == self.auth.user.id query = self.db.alt_logins.oiduser == self.auth.user.id
alt_logins = self.db(query).select() alt_logins = self.db(query).select()
l = [] l = []
for alt_login in alt_logins: for alt_login in alt_logins:
@@ -529,7 +532,7 @@ class Web2pyStore(OpenIDStore):
self.database.define_table(self.table_oid_nonces_name, self.database.define_table(self.table_oid_nonces_name,
Field('server_url', Field('server_url',
'string', length=2047, required=True), 'string', length=2047, required=True),
Field('timestamp', Field('itimestamp',
'integer', required=True), 'integer', required=True),
Field('salt', 'string', Field('salt', 'string',
length=40, required=True) length=40, required=True)
@@ -591,12 +594,12 @@ class Web2pyStore(OpenIDStore):
db = self.database db = self.database
if abs(timestamp - time.time()) > nonce.SKEW: if abs(timestamp - time.time()) > nonce.SKEW:
return False return False
query = (db.oid_nonces.server_url == server_url) & (db.oid_nonces.timestamp == timestamp) & (db.oid_nonces.salt == salt) query = (db.oid_nonces.server_url == server_url) & (db.oid_nonces.itimestamp == timestamp) & (db.oid_nonces.salt == salt)
if db(query).count() > 0: if db(query).count() > 0:
return False return False
else: else:
db.oid_nonces.insert(server_url=server_url, db.oid_nonces.insert(server_url=server_url,
timestamp=timestamp, itimestamp=timestamp,
salt=salt) salt=salt)
return True return True
@@ -628,7 +631,7 @@ class Web2pyStore(OpenIDStore):
""" """
db = self.database db = self.database
query = (db.oid_nonces.timestamp < time.time() - nonce.SKEW) query = (db.oid_nonces.itimestamp < time.time() - nonce.SKEW)
return db(query).delete() return db(query).delete()
def cleanupAssociations(self): def cleanupAssociations(self):