fixed issue 1252, thanks Mark Weissen
This commit is contained in:
@@ -1 +1 @@
|
|||||||
Version 2.4.1-alpha.2+timestamp.2013.01.08.08.48.34
|
Version 2.4.1-alpha.2+timestamp.2013.01.08.08.57.51
|
||||||
|
|||||||
@@ -129,18 +129,21 @@ class OpenIDAuth(object):
|
|||||||
def _define_alt_login_table(self):
|
def _define_alt_login_table(self):
|
||||||
"""
|
"""
|
||||||
Define the OpenID login table.
|
Define the OpenID login table.
|
||||||
Note: type is what I used for our project. We're going to support 'fackbook' and
|
Note: oidtype is what I used for our project.
|
||||||
'plurk' alternate login methods. Otherwise it's always 'openid' and you
|
We're going to support 'fackbook' and
|
||||||
|
'plurk' alternate login methods.
|
||||||
|
Otherwise it's always 'openid' and you
|
||||||
may not need it. This should be easy to changed.
|
may not need it. This should be easy to changed.
|
||||||
(Just remove the field of "type" and remove the
|
(Just remove the field of "type" and remove the
|
||||||
"and db.alt_logins.type == type_" in _find_matched_openid function)
|
"and db.alt_logins.oidtype == type_"
|
||||||
|
in _find_matched_openid function)
|
||||||
"""
|
"""
|
||||||
db = self.db
|
db = self.db
|
||||||
table = db.define_table(
|
table = db.define_table(
|
||||||
self.table_alt_logins_name,
|
self.table_alt_logins_name,
|
||||||
Field('username', length=512, default=''),
|
Field('username', length=512, default=''),
|
||||||
Field('type', length=128, default='openid', readable=False),
|
Field('oidtype', length=128, default='openid', readable=False),
|
||||||
Field('user', self.table_user, readable=False),
|
Field('oiduser', self.table_user, readable=False),
|
||||||
)
|
)
|
||||||
table.username.requires = IS_NOT_IN_DB(db, table.username)
|
table.username.requires = IS_NOT_IN_DB(db, table.username)
|
||||||
self.table_alt_logins = table
|
self.table_alt_logins = table
|
||||||
@@ -213,7 +216,7 @@ class OpenIDAuth(object):
|
|||||||
|
|
||||||
# Get existed OpenID user
|
# Get existed OpenID user
|
||||||
user = db(
|
user = db(
|
||||||
self.table_user.id == alt_login.user).select().first()
|
self.table_user.id == alt_login.oiduser).select().first()
|
||||||
if user:
|
if user:
|
||||||
if current.session.w2popenid:
|
if current.session.w2popenid:
|
||||||
del(current.session.w2popenid)
|
del(current.session.w2popenid)
|
||||||
@@ -230,7 +233,7 @@ class OpenIDAuth(object):
|
|||||||
Get the matched OpenID for given
|
Get the matched OpenID for given
|
||||||
"""
|
"""
|
||||||
query = (
|
query = (
|
||||||
(db.alt_logins.username == oid) & (db.alt_logins.type == type_))
|
(db.alt_logins.username == oid) & (db.alt_logins.oidtype == type_))
|
||||||
alt_login = db(query).select().first() # Get the OpenID record
|
alt_login = db(query).select().first() # Get the OpenID record
|
||||||
return alt_login
|
return alt_login
|
||||||
|
|
||||||
@@ -239,7 +242,7 @@ class OpenIDAuth(object):
|
|||||||
Associate the user logged in with given OpenID
|
Associate the user logged in with given OpenID
|
||||||
"""
|
"""
|
||||||
# print "[DB] %s authenticated" % oid
|
# print "[DB] %s authenticated" % oid
|
||||||
self.db.alt_logins.insert(username=oid, user=user.id)
|
self.db.alt_logins.insert(username=oid, oiduser=user.id)
|
||||||
|
|
||||||
def _form_with_notification(self):
|
def _form_with_notification(self):
|
||||||
"""
|
"""
|
||||||
@@ -400,7 +403,7 @@ width: 400px;
|
|||||||
if 'delete_openid' in request.vars:
|
if 'delete_openid' in request.vars:
|
||||||
self.remove_openid(request.vars.delete_openid)
|
self.remove_openid(request.vars.delete_openid)
|
||||||
|
|
||||||
query = self.db.alt_logins.user == self.auth.user.id
|
query = self.db.alt_logins.oiduser == self.auth.user.id
|
||||||
alt_logins = self.db(query).select()
|
alt_logins = self.db(query).select()
|
||||||
l = []
|
l = []
|
||||||
for alt_login in alt_logins:
|
for alt_login in alt_logins:
|
||||||
@@ -529,7 +532,7 @@ class Web2pyStore(OpenIDStore):
|
|||||||
self.database.define_table(self.table_oid_nonces_name,
|
self.database.define_table(self.table_oid_nonces_name,
|
||||||
Field('server_url',
|
Field('server_url',
|
||||||
'string', length=2047, required=True),
|
'string', length=2047, required=True),
|
||||||
Field('timestamp',
|
Field('itimestamp',
|
||||||
'integer', required=True),
|
'integer', required=True),
|
||||||
Field('salt', 'string',
|
Field('salt', 'string',
|
||||||
length=40, required=True)
|
length=40, required=True)
|
||||||
@@ -591,12 +594,12 @@ class Web2pyStore(OpenIDStore):
|
|||||||
db = self.database
|
db = self.database
|
||||||
if abs(timestamp - time.time()) > nonce.SKEW:
|
if abs(timestamp - time.time()) > nonce.SKEW:
|
||||||
return False
|
return False
|
||||||
query = (db.oid_nonces.server_url == server_url) & (db.oid_nonces.timestamp == timestamp) & (db.oid_nonces.salt == salt)
|
query = (db.oid_nonces.server_url == server_url) & (db.oid_nonces.itimestamp == timestamp) & (db.oid_nonces.salt == salt)
|
||||||
if db(query).count() > 0:
|
if db(query).count() > 0:
|
||||||
return False
|
return False
|
||||||
else:
|
else:
|
||||||
db.oid_nonces.insert(server_url=server_url,
|
db.oid_nonces.insert(server_url=server_url,
|
||||||
timestamp=timestamp,
|
itimestamp=timestamp,
|
||||||
salt=salt)
|
salt=salt)
|
||||||
return True
|
return True
|
||||||
|
|
||||||
@@ -628,7 +631,7 @@ class Web2pyStore(OpenIDStore):
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
db = self.database
|
db = self.database
|
||||||
query = (db.oid_nonces.timestamp < time.time() - nonce.SKEW)
|
query = (db.oid_nonces.itimestamp < time.time() - nonce.SKEW)
|
||||||
return db(query).delete()
|
return db(query).delete()
|
||||||
|
|
||||||
def cleanupAssociations(self):
|
def cleanupAssociations(self):
|
||||||
|
|||||||
Reference in New Issue
Block a user