Mercurial > traipse_dev
view plugins/cherrypy/lib/csauthenticate.py @ 190:15488fe94f52 beta
Traipse Beta 'OpenRPG' {100125-01}
Traipse is a distribution of OpenRPG that is designed to be easy to
setup and go. Traipse also makes it easy for developers to work on code
without fear of sacrifice. 'Ornery-Orc' continues the trend of 'Grumpy'
and adds fixes to the code. 'Ornery-Orc's main goal is to offer more
advanced features and enhance the productivity of the user.
Update Summary (Beta)
New Features:
New Bookmarks Feature
New 'boot' command to remote admin
New confirmation window for sent nodes
Miniatures Layer pop up box allows users to turn off Mini labels, from
FlexiRPG
New Zoom Mouse plugin added
New Images added to Plugin UI
Switching to Element Tree
New Map efficiency, from FlexiRPG
New Status Bar to Update Manager
New TrueDebug Class in orpg_log (See documentation for usage)
New Portable Mercurial
New Tip of the Day, from Core and community
New Reference Syntax added for custom PC sheets
New Child Reference for gametree
New Parent Reference for gametree
New Gametree Recursion method, mapping, context sensitivity, and
effeciency..
New Features node with bonus nodes and Node Referencing help added
New Dieroller structure from Core
New DieRoller portability for odd Dice
New 7th Sea die roller; ie [7k3] = [7d10.takeHighest(3).open(10)]
New 'Mythos' System die roller added
New vs. die roller method for WoD; ie [3v3] = [3d10.vs(3)]. Included for
Mythos roller also
New Warhammer FRPG Die Roller (Special thanks to Puu-san for the
support)
New EZ_Tree Reference system. Push a button, Traipse the tree, get a
reference (Beta!)
New Grids act more like Spreadsheets in Use mode, with Auto Calc
Fixes:
Fix to allow for portability to an OpenSUSE linux OS
Fix to mplay_client for Fedora and OpenSUSE
Fix to Text based Server
Fix to Remote Admin Commands
Fix to Pretty Print, from Core
Fix to Splitter Nodes not being created
Fix to massive amounts of images loading, from Core
Fix to Map from gametree not showing to all clients
Fix to gametree about menus
Fix to Password Manager check on startup
Fix to PC Sheets from tool nodes. They now use the tabber_panel
Fix to Whiteboard ID to prevent random line or text deleting.
Fixes to Server, Remote Server, and Server GUI
Fix to Update Manager; cleaner clode for saved repositories
Fixes made to Settings Panel and now reactive settings when Ok is
pressed
Fixes to Alternity roller's attack roll. Uses a simple Tuple instead of
a Splice
Fix to Use panel of Forms and Tabbers. Now longer enters design mode
Fix made Image Fetching. New fetching image and new failed image
Fix to whiteboard ID's to prevent non updated clients from ruining the
fix.
default_manifest.xml renamed to default_upmana.xml
author | sirebral |
---|---|
date | Mon, 25 Jan 2010 12:07:48 -0600 |
parents | 4385a7d0efd1 |
children |
line wrap: on
line source
""" Copyright (c) 2004, CherryPy Team (team@cherrypy.org) All rights reserved. Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: * Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. * Neither the name of the CherryPy Team nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. """ import time, whrandom from cherrypy import cpg from aspect import Aspect, STOP, CONTINUE class CSAuthenticate(Aspect): timeoutMessage = "Session timed out" wrongLoginPasswordMessage = "Wrong login/password" noCookieMessage = "No cookie" logoutMessage = "You have been logged out" sessionIdCookieName = "CherrySessionId" timeout = 60 # in minutes def _before(self, methodName, method): # If the method is not exposed, don't do anything if not getattr(method, 'exposed', None): return CONTINUE, None cpg.request.login = '' # If the method is one of these 4, do not try to find out who is logged in if methodName in ["loginScreen", "logoutScreen", "doLogin", "doLogout"]: return CONTINUE, None # Check if a user is logged in: # - If they are, set request.login with the right value # - If not, return the login screen if not cpg.request.simpleCookie.has_key(self.sessionIdCookieName): return STOP, self.loginScreen(self.noCookieMessage, cpg.request.browserUrl) sessionId = cpg.request.simpleCookie[self.sessionIdCookieName].value now=time.time() # Check that session exists and hasn't timed out timeout=0 if not cpg.request.sessionMap.has_key(sessionId): return STOP, self.loginScreen(self.noCookieMessage, cpg.request.browserUrl) else: login, expire = cpg.request.sessionMap[sessionId] if expire < now: timeout=1 else: expire = now + self.timeout*60 cpg.request.sessionMap[sessionId] = login, expire if timeout: return STOP, self.loginScreen(self.timeoutMessage, cpg.request.browserUrl) cpg.request.login = login return CONTINUE, None def checkLoginAndPassword(self, login, password): if (login,password) == ('login','password'): return '' return 'Wrong login/password' def generateSessionId(self, sessionIdList): choice="0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ" while 1: sessionId="" for dummy in range(20): sessionId += whrandom.choice(choice) if sessionId not in sessionIdList: return sessionId def doLogin(self, login, password, fromPage): # Check that login/password match errorMsg = self.checkLoginAndPassword(login, password) if errorMsg: cpg.request.login = '' return self.loginScreen(errorMsg, fromPage, login) cpg.request.login = login # Set session newSessionId = self.generateSessionId(cpg.request.sessionMap.keys()) cpg.request.sessionMap[newSessionId] = login, time.time()+self.timeout*60 cpg.response.simpleCookie[self.sessionIdCookieName] = newSessionId cpg.response.simpleCookie[self.sessionIdCookieName]['path'] = '/' cpg.response.simpleCookie[self.sessionIdCookieName]['max-age'] = 31536000 cpg.response.simpleCookie[self.sessionIdCookieName]['version'] = 1 cpg.response.headerMap['Status'] = 302 cpg.response.headerMap['Location'] = fromPage return "" doLogin.exposed = True def doLogout(self): try: sessionId = request.simpleCookie[self.sessionIdCookieName].value del request.sessionMap[sessionId] except: pass cpg.response.simpleCookie[self.sessionIdCookieName] = "" cpg.response.simpleCookie[self.sessionIdCookieName]['path'] = '/' cpg.response.simpleCookie[self.sessionIdCookieName]['max-age'] = 0 cpg.response.simpleCookie[self.sessionIdCookieName]['version'] = 1 cpg.request.login = '' cpg.response.headerMap['Status'] = 302 cpg.response.headerMap['Location'] = 'logoutScreen' # TBCTBC: may not be the right URL return "" doLogout.exposed = True def logoutScreen(self): return self.loginScreen(self.logoutMessage, '/index') # TBC logoutScreen.exposed = True def loginScreen(self, message, fromPage, login=''): return """ <html><body> Message: %s <form method="post" action="doLogin"> Login: <input type=text name=login value="%s" size=10><br /> Password: <input type=password name=password size=10><br /> <input type=hidden name=fromPage value="%s"><br /> <input type=submit> </form> </body></html> """ % (message, login, fromPage) loginScreen.exposed = True