login_2fa.py 2.4 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273
  1. from .tool.func import *
  2. def login_2fa_2(conn):
  3. curs = conn.cursor()
  4. if not (flask.session and 'b_id' in flask.session):
  5. return redirect('/user')
  6. ip = ip_check()
  7. if ip_or_user(ip) == 0:
  8. return redirect('/user')
  9. if ban_check(tool = 'login') == 1:
  10. return re_error('/ban')
  11. if flask.request.method == 'POST':
  12. if captcha_post(flask.request.form.get('g-recaptcha-response', flask.request.form.get('g-recaptcha', ''))) == 1:
  13. return re_error('/error/13')
  14. else:
  15. captcha_post('', 0)
  16. agent = flask.request.headers.get('User-Agent')
  17. user_id = flask.session['b_id']
  18. curs.execute(db_change('select data from user_set where name = "2fa_pw" and id = ?'), [user_id])
  19. user_1 = curs.fetchall()[0][0]
  20. curs.execute(db_change('select data from user_set where name = "2fa_pw_encode" and id = ?'), [user_id])
  21. user_2 = curs.fetchall()[0][0]
  22. pw_check_d = pw_check(
  23. flask.request.form.get('pw', ''),
  24. user_1,
  25. user_2,
  26. user_id
  27. )
  28. if pw_check_d != 1:
  29. return re_error('/error/10')
  30. flask.session['head'] = flask.session['b_head']
  31. flask.session['id'] = user_id
  32. curs.execute(db_change("insert into ua_d (name, ip, ua, today, sub) values (?, ?, ?, ?, '')"), [
  33. user_id,
  34. ip,
  35. agent,
  36. get_time()
  37. ])
  38. conn.commit()
  39. flask.session.pop('b_id', None)
  40. flask.session.pop('b_head', None)
  41. return redirect('/user')
  42. else:
  43. http_warring = '' + \
  44. '<hr class="main_hr">' + \
  45. '<span>' + load_lang('http_warring') + '</span>' + \
  46. ''
  47. return easy_minify(flask.render_template(skin_check(),
  48. imp = [load_lang('login'), wiki_set(), custom(), other2([0, 0])],
  49. data = '''
  50. <form method="post">
  51. <input placeholder="''' + load_lang('2fa_password') + '''" name="pw" type="password">
  52. <hr class=\"main_hr\">
  53. ''' + captcha_get() + '''
  54. <button type="submit">''' + load_lang('login') + '''</button>
  55. ''' + http_warring + '''
  56. </form>
  57. ''',
  58. menu = [['user', load_lang('return')]]
  59. ))