mirror of
https://github.com/zoffline/zwift-offline.git
synced 2026-07-30 23:50:20 -07:00
Merge pull request #268 from zoffline/dependabot/pip/werkzeug-3.0.1
Bump werkzeug from 2.3.7 to 3.0.1
This commit is contained in:
+2
-2
@@ -1,5 +1,5 @@
|
||||
flask==2.3.2
|
||||
flask-login==0.6.2
|
||||
flask-login==0.6.3
|
||||
flask_sqlalchemy==3.0.3
|
||||
gevent==23.9.1
|
||||
protobuf==4.21.12
|
||||
@@ -8,4 +8,4 @@ pyjwt==2.6.0
|
||||
stravalib==1.1.0
|
||||
dnspython==2.3.0
|
||||
fitdecode==0.10.0
|
||||
werkzeug==2.3.7
|
||||
werkzeug==3.0.1
|
||||
|
||||
+24
-5
@@ -599,6 +599,15 @@ def signup():
|
||||
return render_template("signup.html")
|
||||
|
||||
|
||||
def check_sha256_hash(pwhash, password):
|
||||
import hmac
|
||||
try:
|
||||
method, salt, hashval = pwhash.split("$", 2)
|
||||
except ValueError:
|
||||
return False
|
||||
return hmac.compare_digest(hmac.new(salt.encode("utf-8"), password.encode("utf-8"), method).hexdigest(), hashval)
|
||||
|
||||
|
||||
@app.route("/login/", methods=["GET", "POST"])
|
||||
def login():
|
||||
if request.method == "POST":
|
||||
@@ -612,9 +621,15 @@ def login():
|
||||
|
||||
user = User.query.filter_by(username=username).first()
|
||||
|
||||
if user and check_password_hash(user.pass_hash, password):
|
||||
if user.pass_hash.startswith('sha256'):
|
||||
if user and user.pass_hash.startswith('sha256'): # sha256 is deprecated in werkzeug 3
|
||||
if check_sha256_hash(user.pass_hash, password):
|
||||
user.pass_hash = generate_password_hash(password, 'scrypt')
|
||||
db.session.commit()
|
||||
else:
|
||||
flash("Invalid username or password.")
|
||||
return redirect(url_for('login'))
|
||||
|
||||
if user and check_password_hash(user.pass_hash, password):
|
||||
login_user(user, remember=True)
|
||||
user.remember = remember
|
||||
db.session.commit()
|
||||
@@ -629,7 +644,7 @@ def login():
|
||||
else:
|
||||
flash("Invalid username or password.")
|
||||
|
||||
if current_user.is_authenticated and current_user.remember and not current_user.pass_hash.startswith('sha256'):
|
||||
if current_user.is_authenticated and current_user.remember:
|
||||
return redirect(url_for("user_home", username=current_user.username, enable_ghosts=bool(current_user.enable_ghosts), online=get_online()))
|
||||
|
||||
user = User.verify_token(request.args.get('token'))
|
||||
@@ -3663,10 +3678,14 @@ def auth_realms_zwift_protocol_openid_connect_token():
|
||||
if username and MULTIPLAYER:
|
||||
user = User.query.filter_by(username=username).first()
|
||||
|
||||
if user and check_password_hash(user.pass_hash, password):
|
||||
if user.pass_hash.startswith('sha256'):
|
||||
if user and user.pass_hash.startswith('sha256'): # sha256 is deprecated in werkzeug 3
|
||||
if check_sha256_hash(user.pass_hash, password):
|
||||
user.pass_hash = generate_password_hash(password, 'scrypt')
|
||||
db.session.commit()
|
||||
else:
|
||||
return '', 401
|
||||
|
||||
if user and check_password_hash(user.pass_hash, password):
|
||||
login_user(user, remember=True)
|
||||
else:
|
||||
return '', 401
|
||||
|
||||
Reference in New Issue
Block a user