修复了在实际部署环境中,请求可能命中不同进程导致的登录报错
This commit is contained in:
@@ -90,4 +90,26 @@ def verify_password(password_plain: str, salt_b64: str, hash_b64: str) -> bool:
|
||||
actual = hash_password_with_salt(password_plain, salt)
|
||||
return hmac.compare_digest(actual, expected)
|
||||
except Exception:
|
||||
return False
|
||||
return False
|
||||
|
||||
def generate_rsa_private_pem_b64() -> str:
|
||||
if rsa is None or serialization is None:
|
||||
raise RuntimeError("cryptography library is required for RSA operations")
|
||||
priv = rsa.generate_private_key(public_exponent=65537, key_size=2048)
|
||||
pem = priv.private_bytes(encoding=serialization.Encoding.PEM, format=serialization.PrivateFormat.PKCS8, encryption_algorithm=serialization.NoEncryption())
|
||||
return base64.b64encode(pem).decode('ascii')
|
||||
|
||||
def public_spki_b64_from_private_pem_b64(private_pem_b64: str) -> str:
|
||||
if serialization is None:
|
||||
raise RuntimeError("cryptography library is required for RSA operations")
|
||||
priv = serialization.load_pem_private_key(base64.b64decode(private_pem_b64), password=None)
|
||||
pub = priv.public_key()
|
||||
spki = pub.public_bytes(encoding=serialization.Encoding.DER, format=serialization.PublicFormat.SubjectPublicKeyInfo)
|
||||
return base64.b64encode(spki).decode('ascii')
|
||||
|
||||
def rsa_oaep_decrypt_b64_with_private_pem(private_pem_b64: str, ciphertext_b64: str) -> bytes:
|
||||
if serialization is None or padding is None or hashes is None:
|
||||
raise RuntimeError("cryptography library is required for RSA operations")
|
||||
priv = serialization.load_pem_private_key(base64.b64decode(private_pem_b64), password=None)
|
||||
ct = base64.b64decode(ciphertext_b64)
|
||||
return priv.decrypt(ct, padding.OAEP(mgf=padding.MGF1(algorithm=hashes.SHA256()), algorithm=hashes.SHA256(), label=None))
|
||||
Reference in New Issue
Block a user