revent register and other form from ever sending back a password, thanks Anthony

This commit is contained in:
mdipierro
2014-08-27 14:35:36 -05:00
parent d04a3e62ae
commit 5364193759
4 changed files with 12 additions and 10 deletions
+5 -1
View File
@@ -109,6 +109,7 @@ __all__ = [
'embed64', 'embed64',
] ]
DEFAULT_PASSWORD_DISPLAY = '*' * 8
def xmlescape(data, quote=True): def xmlescape(data, quote=True):
""" """
@@ -1858,7 +1859,7 @@ class INPUT(DIV):
break break
if not name in self.errors: if not name in self.errors:
self.vars[name] = value self.vars[name] = value
return True return True
return False return False
def _postprocessing(self): def _postprocessing(self):
@@ -1889,12 +1890,15 @@ class INPUT(DIV):
self['_checked'] = 'checked' self['_checked'] = 'checked'
else: else:
self['_checked'] = None self['_checked'] = None
elif t == 'password' and value != DEFAULT_PASSWORD_DISPLAY:
self['value'] = ''
elif not t == 'submit': elif not t == 'submit':
if value is None: if value is None:
self['value'] = _value self['value'] = _value
elif not isinstance(value, list): elif not isinstance(value, list):
self['_value'] = value self['_value'] = value
def xml(self): def xml(self):
name = self.attributes.get('_name', None) name = self.attributes.get('_name', None)
if name and hasattr(self, 'errors') \ if name and hasattr(self, 'errors') \
+2 -2
View File
@@ -365,9 +365,9 @@ def wsgibase(environ, responder):
client = client, client = client,
folder = abspath('applications', app) + os.sep, folder = abspath('applications', app) + os.sep,
ajax = x_req_with == 'xmlhttprequest', ajax = x_req_with == 'xmlhttprequest',
cid = env.http_web2py_component_element, cid = env.http_web2py_component_element,
is_local = (env.remote_addr in local_hosts and is_local = (env.remote_addr in local_hosts and
request.client == env.remote_addr), client == env.remote_addr),
is_shell = cmd_opts and cmd_opts.shell, is_shell = cmd_opts and cmd_opts.shell,
is_sheduler = cmd_opts and cmd_opts.scheduler, is_sheduler = cmd_opts and cmd_opts.scheduler,
is_https = env.wsgi_url_scheme in HTTPS_SCHEMES or \ is_https = env.wsgi_url_scheme in HTTPS_SCHEMES or \
+4 -7
View File
@@ -19,7 +19,7 @@ from gluon.http import HTTP
from gluon.html import XmlComponent from gluon.html import XmlComponent
from gluon.html import XML, SPAN, TAG, A, DIV, CAT, UL, LI, TEXTAREA, BR, IMG, SCRIPT, P from gluon.html import XML, SPAN, TAG, A, DIV, CAT, UL, LI, TEXTAREA, BR, IMG, SCRIPT, P
from gluon.html import FORM, INPUT, LABEL, OPTION, SELECT, COL, COLGROUP from gluon.html import FORM, INPUT, LABEL, OPTION, SELECT, COL, COLGROUP
from gluon.html import TABLE, THEAD, TBODY, TR, TD, TH, STYLE from gluon.html import TABLE, THEAD, TBODY, TR, TD, TH, STYLE, DEFAULT_PASSWORD_DISPLAY
from gluon.html import URL, truncate_string, FIELDSET from gluon.html import URL, truncate_string, FIELDSET
from gluon.dal import DAL, Field, Table, Row, CALLABLETYPES, smart_query, \ from gluon.dal import DAL, Field, Table, Row, CALLABLETYPES, smart_query, \
bar_encode, Reference, Expression, SQLCustomType, sqlhtml_validators, \ bar_encode, Reference, Expression, SQLCustomType, sqlhtml_validators, \
@@ -474,8 +474,6 @@ class CheckboxesWidget(OptionsWidget):
class PasswordWidget(FormWidget): class PasswordWidget(FormWidget):
_class = 'password' _class = 'password'
DEFAULT_PASSWORD_DISPLAY = 8 * ('*')
@classmethod @classmethod
def widget(cls, field, value, **attributes): def widget(cls, field, value, **attributes):
""" """
@@ -488,7 +486,7 @@ class PasswordWidget(FormWidget):
# detect if attached a IS_STRONG with entropy # detect if attached a IS_STRONG with entropy
default = dict( default = dict(
_type='password', _type='password',
_value=(value and cls.DEFAULT_PASSWORD_DISPLAY) or '', _value=(value and DEFAULT_PASSWORD_DISPLAY) or '',
) )
attr = cls._attributes(field, default, **attributes) attr = cls._attributes(field, default, **attributes)
@@ -1233,7 +1231,7 @@ class SQLFORM(FORM):
elif field.type == 'password': elif field.type == 'password':
inp = self.widgets.password.widget(field, default) inp = self.widgets.password.widget(field, default)
if self.record: if self.record:
dspval = PasswordWidget.DEFAULT_PASSWORD_DISPLAY dspval = DEFAULT_PASSWORD_DISPLAY
else: else:
dspval = '' dspval = ''
elif field.type == 'blob': elif field.type == 'blob':
@@ -1548,8 +1546,7 @@ class SQLFORM(FORM):
else: else:
self.vars[fieldname] = fields[fieldname] = False self.vars[fieldname] = fields[fieldname] = False
elif field.type == 'password' and self.record\ elif field.type == 'password' and self.record\
and request_vars.get(fieldname, None) == \ and request_vars.get(fieldname, None) == DEFAULT_PASSWORD_DISPLAY:
PasswordWidget.DEFAULT_PASSWORD_DISPLAY:
continue # do not update if password was not changed continue # do not update if password was not changed
elif field.type == 'upload': elif field.type == 'upload':
f = self.vars[fieldname] f = self.vars[fieldname]
+1
View File
@@ -2780,6 +2780,7 @@ class Auth(object):
else: else:
next = replace_id(next, form) next = replace_id(next, form)
redirect(next, client_side=self.settings.client_side) redirect(next, client_side=self.settings.client_side)
return form return form
def is_logged_in(self): def is_logged_in(self):