def signin():
    # Issues authorization code
    username = request.form.get("username")
    password = request.form.get("password")
    client_id = request.form.get("client_id")
    redirect_url = request.form.get("redirect_url")

    if None in [username, password, client_id, redirect_url]:
        return json.dumps({"error": "invalid_request"}), 400

    if not verify_client_info(client_id, redirect_url):
        return json.dumps({"error": "invalid_client"})

    if not authenticate_user_credentials(username, password):
        return json.dumps({"error": "access_denied"}), 401

    access_token = generate_access_token()

    print(process_redirect_url(redirect_url, {"1": "2"}))

    return redirect(
        process_redirect_url(
            redirect_url,
            {
                "access_token": access_token,
                "token_type": "JWT",
                "expires_in": JWT_LIFE_SPAN,
            },
        ),
        code=303,
    )
Пример #2
0
def signin():
    # Issues authorization code
    username = request.form.get('username')
    password = request.form.get('password')
    client_id = request.form.get('client_id')
    redirect_url = request.form.get('redirect_url')

    if None in [username, password, client_id, redirect_url]:
        return json.dumps({"error": "invalid_request"}), 400

    if not verify_client_info(client_id, redirect_url):
        return json.dumps({"error": "invalid_client"})

    if not authenticate_user_credentials(username, password):
        return json.dumps({'error': 'access_denied'}), 401

    access_token = generate_access_token()

    print(process_redirect_url(redirect_url, {"1": "2"}))

    return redirect(process_redirect_url(
        redirect_url, {
            'access_token': access_token,
            'token_type': 'JWT',
            'expires_in': JWT_LIFE_SPAN
        }),
                    code=303)
Пример #3
0
def auth():
  # Issues access token
  username = request.form.get('username')
  password = request.form.get('password')
  client_id = request.form.get('client_id')
  client_secret = request.form.get('client_secret')

  if None in [username, password, client_id, client_secret]:
    return json.dumps({
      "error": "invalid_request"
    }), 400
  
  if not authenticate_user_credentials(username, password):
    return json.dumps({
      "error": "access_denied"
    }), 401
  
  if not authenticate_client(client_id, client_secret):
    return json.dumps({
      "error": "invalid_client"
    }), 400

  access_token = generate_access_token()
  return json.dumps({ 
    "access_token": access_token,
    "token_type": "JWT",
    "expires_in": LIFE_SPAN
  })
def signin():
    # Issues authorization code
    username = request.form.get('username')
    password = request.form.get('password')
    client_id = request.form.get('client_id')
    redirect_url = request.form.get('redirect_url')
    code_challenge = request.form.get('code_challenge')
    state = request.form.get('state')

    if None in [
            username, password, client_id, redirect_url, code_challenge, state
    ]:
        return json.dumps({"error": "invalid_request"}), 400

    if not verify_client_info(client_id, redirect_url):
        return json.dumps({"error": "invalid_client"})

    # Do the database check over here
    if not authenticate_user_credentials(username, password):
        return json.dumps({'error': 'access_denied'}), 401

    authorization_code = generate_authorization_code(client_id, redirect_url,
                                                     code_challenge, state)

    url = process_redirect_url(redirect_url, authorization_code, state)

    return redirect(url, code=303)
Пример #5
0
def signin():
    # Issues authorization code
    username = request.form.get("username")
    password = request.form.get("password")
    client_id = request.form.get("client_id")
    redirect_url = request.form.get("redirect_url")

    if None in [username, password, client_id, redirect_url]:
        return json.dumps({"error": "invalid_request"}), 400

    if not verify_client_info(client_id, redirect_url):
        return json.dumps({"error": "invalid_client"})

    if not authenticate_user_credentials(username, password):
        return json.dumps({"error": "access_denied"}), 401

    authorization_code = generate_authorization_code(client_id, redirect_url)

    url = process_redirect_url(redirect_url, authorization_code)

    return redirect(url, code=303)