2
0

login_login_2fa.py 2.5 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071
  1. from .tool.func import *
  2. def login_login_2fa_2(conn):
  3. with get_db_connect() as conn:
  4. curs = conn.cursor()
  5. # email 2fa
  6. # pw 2fa
  7. # q_a 2fa
  8. if not (flask.session and 'login_id' in flask.session):
  9. return redirect('/user')
  10. ip = ip_check()
  11. if ip_or_user(ip) == 0:
  12. return redirect('/user')
  13. if ban_check(None, 'login') == 1:
  14. return re_error('/ban')
  15. if flask.request.method == 'POST':
  16. if captcha_post(flask.request.form.get('g-recaptcha-response', flask.request.form.get('g-recaptcha', ''))) == 1:
  17. return re_error('/error/13')
  18. else:
  19. captcha_post('', 0)
  20. user_agent = flask.request.headers.get('User-Agent', '')
  21. user_id = flask.session['login_id']
  22. curs.execute(db_change('select data from user_set where name = "2fa_pw" and id = ?'), [user_id])
  23. user_1 = curs.fetchall()
  24. if user_1:
  25. curs.execute(db_change('select data from user_set where name = "2fa_pw_encode" and id = ?'), [user_id])
  26. user_1 = user_1[0][0]
  27. user_2 = curs.fetchall()[0][0]
  28. pw_check_d = pw_check(
  29. flask.request.form.get('pw', ''),
  30. user_1,
  31. user_2,
  32. user_id
  33. )
  34. if pw_check_d != 1:
  35. return re_error('/error/10')
  36. flask.session['id'] = user_id
  37. ua_plus(
  38. user_id,
  39. ip,
  40. user_agent,
  41. get_time()
  42. )
  43. conn.commit()
  44. flask.session.pop('b_id', None)
  45. return redirect('/user')
  46. else:
  47. return easy_minify(flask.render_template(skin_check(),
  48. imp = [load_lang('login'), wiki_set(), wiki_custom(), wiki_css([0, 0])],
  49. data = '''
  50. <form method="post">
  51. <input placeholder="''' + load_lang('2fa_password') + '''" name="pw" type="password">
  52. <hr class="main_hr">
  53. ''' + captcha_get() + '''
  54. <button type="submit">''' + load_lang('login') + '''</button>
  55. ''' + http_warning() + '''
  56. </form>
  57. ''',
  58. menu = [['user', load_lang('return')]]
  59. ))