mirror of
https://github.com/wassname/flask-security.git
synced 2026-08-07 11:22:21 +08:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
316d945d96 | ||
|
|
6eb77c06ad | ||
|
|
35fd08772b |
@@ -3,6 +3,14 @@ Flask-Security Changelog
|
||||
|
||||
Here you can see the full list of changes between each Flask-Security release.
|
||||
|
||||
Version 1.7.1
|
||||
-------------
|
||||
|
||||
Released January 14th 2014
|
||||
|
||||
- Fixed a bug where passwords would fail to verify when specifying a password hash algorithm
|
||||
|
||||
|
||||
Version 1.7.0
|
||||
-------------
|
||||
|
||||
|
||||
+1
-1
@@ -49,7 +49,7 @@ copyright = u'2012, Matt Wright'
|
||||
# built documents.
|
||||
#
|
||||
# The short X.Y version.
|
||||
version = '1.7.0'
|
||||
version = '1.7.1'
|
||||
# The full version, including alpha/beta/rc tags.
|
||||
release = version
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@
|
||||
:license: MIT, see LICENSE for more details.
|
||||
"""
|
||||
|
||||
__version__ = '1.7.0'
|
||||
__version__ = '1.7.1'
|
||||
|
||||
from .core import Security, RoleMixin, UserMixin, AnonymousUser, current_user
|
||||
from .datastore import SQLAlchemyUserDatastore, MongoEngineUserDatastore, PeeweeUserDatastore
|
||||
|
||||
@@ -121,7 +121,10 @@ def verify_and_update_password(password, user):
|
||||
:param password: A plaintext password to verify
|
||||
:param user: The user to verify against
|
||||
"""
|
||||
verified, new_password = _pwd_context.verify_and_update(encrypt_password(password), user.password)
|
||||
|
||||
if _security.password_hash != 'plaintext':
|
||||
password = get_hmac(password)
|
||||
verified, new_password = _pwd_context.verify_and_update(password, user.password)
|
||||
if verified and new_password:
|
||||
user.password = new_password
|
||||
_datastore.put(user)
|
||||
@@ -135,8 +138,8 @@ def encrypt_password(password):
|
||||
"""
|
||||
if _security.password_hash == 'plaintext':
|
||||
return password
|
||||
signed = get_hmac(password)
|
||||
return _pwd_context.encrypt(signed.decode('ascii'))
|
||||
signed = get_hmac(password).decode('ascii')
|
||||
return _pwd_context.encrypt(signed)
|
||||
|
||||
|
||||
def md5(data):
|
||||
|
||||
@@ -20,7 +20,7 @@ from setuptools import setup
|
||||
|
||||
setup(
|
||||
name='Flask-Security',
|
||||
version='1.7.0',
|
||||
version='1.7.1',
|
||||
url='https://github.com/mattupstate/flask-security',
|
||||
license='MIT',
|
||||
author='Matt Wright',
|
||||
|
||||
+10
-10
@@ -19,18 +19,18 @@ from flask_security.signals import user_registered
|
||||
|
||||
from tests import SecurityTest
|
||||
|
||||
# TODO: Wait for passlib + bcrypt python3 compatibility to be fixed
|
||||
# class ConfiguredPasswordHashSecurityTests(SecurityTest):
|
||||
|
||||
# AUTH_CONFIG = {
|
||||
# 'SECURITY_PASSWORD_HASH': 'bcrypt',
|
||||
# 'SECURITY_PASSWORD_SALT': 'so-salty',
|
||||
# 'USER_COUNT': 1
|
||||
# }
|
||||
class ConfiguredPasswordHashSecurityTests(SecurityTest):
|
||||
|
||||
# def test_authenticate(self):
|
||||
# r = self.authenticate(endpoint="/login")
|
||||
# self.assertIn(b'Home Page', r.data)
|
||||
AUTH_CONFIG = {
|
||||
'SECURITY_PASSWORD_HASH': 'bcrypt',
|
||||
'SECURITY_PASSWORD_SALT': 'so-salty',
|
||||
'USER_COUNT': 1
|
||||
}
|
||||
|
||||
def test_authenticate(self):
|
||||
r = self.authenticate(endpoint="/login")
|
||||
self.assertIn(b'Home Page', r.data)
|
||||
|
||||
|
||||
class ConfiguredSecurityTests(SecurityTest):
|
||||
|
||||
Reference in New Issue
Block a user