login_login_2fa.py 2.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566
  1. from .tool.func import *
  2. def login_login_2fa_2():
  3. with get_db_connect() as conn:
  4. curs = conn.cursor()
  5. # email 2fa
  6. # pw 2fa
  7. # q_a 2fa
  8. if not (flask.session and 'login_id' in flask.session):
  9. return redirect(conn, '/user')
  10. ip = ip_check()
  11. if ip_or_user(ip) == 0:
  12. return redirect(conn, '/user')
  13. if ban_check(conn, None, 'login')[0] == 1:
  14. return re_error(conn, '/ban')
  15. if flask.request.method == 'POST':
  16. if captcha_post(conn, flask.request.form.get('g-recaptcha-response', flask.request.form.get('g-recaptcha', ''))) == 1:
  17. return re_error(conn, '/error/13')
  18. else:
  19. captcha_post(conn, '', 0)
  20. user_agent = flask.request.headers.get('User-Agent', '')
  21. user_id = flask.session['login_id']
  22. user_pw = flask.request.form.get('pw', '')
  23. curs.execute(db_change('select data from user_set where name = "2fa_pw" and id = ?'), [user_id])
  24. user_1 = curs.fetchall()
  25. if user_1:
  26. curs.execute(db_change('select data from user_set where name = "2fa_pw_encode" and id = ?'), [user_id])
  27. user_1 = user_1[0][0]
  28. user_2 = curs.fetchall()[0][0]
  29. pw_check_d = pw_check(conn, user_pw, user_1, user_2, user_id)
  30. if pw_check_d != 1:
  31. return re_error(conn, '/error/10')
  32. flask.session['id'] = user_id
  33. ua_plus(conn,
  34. user_id,
  35. ip,
  36. user_agent,
  37. get_time()
  38. )
  39. flask.session.pop('b_id', None)
  40. return redirect(conn, '/user')
  41. else:
  42. return easy_minify(conn, flask.render_template(skin_check(conn),
  43. imp = [get_lang(conn, 'login'), wiki_set(conn), wiki_custom(conn), wiki_css([0, 0])],
  44. data = '''
  45. <form method="post">
  46. <input placeholder="''' + get_lang(conn, '2fa_password') + '''" name="pw" type="password">
  47. <hr class="main_hr">
  48. ''' + captcha_get(conn) + '''
  49. <button type="submit">''' + get_lang(conn, 'login') + '''</button>
  50. ''' + http_warning(conn) + '''
  51. </form>
  52. ''',
  53. menu = [['user', get_lang(conn, 'return')]]
  54. ))