accounts.py 4.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127
  1. from hmac import new
  2. from unicodedata import category
  3. from flask import Blueprint, render_template, request, flash, redirect, url_for
  4. from flask_login import login_user, login_required, logout_user, current_user
  5. from werkzeug.security import generate_password_hash, check_password_hash
  6. from .models import User
  7. from . import db
  8. from .forms import LoginForm, RegForm, MFAForm, SearchForm
  9. # MFA
  10. import pyotp
  11. accounts = Blueprint('accounts', __name__)
  12. @accounts.route('/login', methods=['GET', 'POST'])
  13. def login():
  14. form = LoginForm()
  15. seform = SearchForm()
  16. if form.validate_on_submit():
  17. email = form.email.data
  18. challenge_passwd = form.passwd.data
  19. # Check fo user in User table
  20. user = User.query.filter_by(email=email).first()
  21. # If there's a user
  22. if user:
  23. if check_password_hash(user.password, challenge_passwd):
  24. return redirect(url_for('accounts.mfa', user_chal = user.id)) # passes user to mfa
  25. else:
  26. flash('Unsucessful Login!', category='error')
  27. else:
  28. flash('Unsucessful Login!', category='error')
  29. return render_template('login.html', user = current_user, form = form, seform = SearchForm())
  30. @accounts.route('/logout')
  31. @login_required
  32. def logout():
  33. logout_user()
  34. return redirect(url_for('accounts.login'))
  35. @accounts.route('/register', methods=['GET', 'POST'])
  36. def register():
  37. pass_list = list()
  38. form = RegForm()
  39. seform = SearchForm()
  40. if form.validate_on_submit():
  41. email = form.email.data
  42. username = form.username.data
  43. passwd_1 = form.passwd_1.data
  44. passwd_2 = form.passwd_2.data
  45. # Basic User Input Checks
  46. email_check = User.query.filter_by(email=email).first()
  47. if len(email) < 1:
  48. flash('Your Email must be longer than 0 characters.', category='error')
  49. elif email_check:
  50. flash('This Email is already taken', category='error')
  51. else:
  52. pass_list.append('p')
  53. if len(username) < 1:
  54. flash('Username must be something', category='error')
  55. else:
  56. pass_list.append('p')
  57. if len(passwd_1) < 8 or len(passwd_2) < 8:
  58. flash('Your Password must be longer than or equal to 8 characters.', category='error')
  59. else:
  60. if passwd_1 != passwd_2:
  61. flash('Your Passwords must match!', category='error')
  62. else:
  63. if len(pass_list) == 2:
  64. new_user = User(email=email,
  65. username=username,
  66. password=generate_password_hash(passwd_2, method='sha256')
  67. )
  68. db.session.add(new_user)
  69. db.session.commit()
  70. flash('Account Registration Successful!', category='success')
  71. return redirect(url_for('dashboards.market'))
  72. else:
  73. flash('Registration Failed', category='error')
  74. return render_template("register.html", user = current_user, form = form, seform = seform)
  75. @accounts.route('/mfa', methods=['GET', 'POST'])
  76. def mfa():
  77. form = MFAForm()
  78. user_chal = request.args['user_chal']
  79. user = User.query.filter_by(id = user_chal).first()
  80. seform = SearchForm()
  81. # check for existing totphash
  82. if not user.totphash:
  83. # generate random secret key for auth
  84. secret = pyotp.random_base32()
  85. # add to User table and show this secret next time.
  86. dbcall = User.query.filter_by(id = user.id).first()
  87. dbcall.totphash = secret
  88. db.session.commit()
  89. flash('Generated new TOTP Secret', category='success')
  90. else: # create a new totphash
  91. secret = user.totphash
  92. challenge_answer = int(pyotp.TOTP(secret).now())
  93. if form.validate_on_submit():
  94. otp = int(form.otp.data)
  95. # checks MFA
  96. if challenge_answer == otp:
  97. flash('Login Successful!', category='sucess')
  98. login_user(user, remember=True)
  99. return redirect(url_for('dashboards.market'))
  100. else:
  101. flash('Login Unsuccessful!', category='error')
  102. return redirect(url_for('accounts.mfa'))
  103. return render_template('mfa.html', secret = secret, form = form, user = user, seform = seform)