【问题标题】:Python3 bcrypt, pymongo, flask ValueError: Invalid saltPython3 bcrypt、pymongo、flask ValueError:无效的盐
【发布时间】:2017-07-31 22:21:44
【问题描述】:

我正在尝试使用烧瓶、bcrypt 和 pymongo 创建一个允许您注册帐户和登录的网站。当前注册正在工作,但登录无效。当我点击登录时,我得到this error。 我的代码:

from flask import Flask, render_template, url_for, request, session, redirect
from flask_pymongo import PyMongo
import bcrypt

app = Flask(__name__)

app.config['MONGO_DBNAME'] = 'websitetest'
app.config['MONGO_URI'] = 'mongodb://localhost:27017'

mongo = PyMongo(app)


@app.route('/')
def index():
    if 'username' in session:
        return('You are logged in as ' + session['username'])

    return render_template('index.html')


@app.route('/login', methods=['POST'])
def login():
    users = mongo.db.users
    login_user = users.find_one({'name': request.form['username']})

    if login_user:
        if bcrypt.hashpw(bytes(request.form['pass'], 'utf-8'), bytes(request.form['pass'], 'utf-8')) == bytes(request.form['pass'], 'utf-8'):
            session['username'] = request.form['username']
            return redirect(url_for('index'))
    return 'Invalid username/password combination.'


@app.route('/register', methods=['POST', 'GET'])
def register():
    if request.method == 'POST':
        users = mongo.db.users
        existing_user = users.find_one({'name': request.form['username']})

        if existing_user is None:
            hashpass = bcrypt.hashpw(request.form['pass'].encode('utf-8'), bcrypt.gensalt())
            users.insert({'name': request.form['username'], 'password': hashpass})
            session['username'] = request.form['username']
            return redirect(url_for('index'))

        return('That username already exists!')

    return render_template('register.html')


if __name__ == '__main__':
    app.secret_key = 'mysecret'
    app.run(debug=True)

任何帮助将不胜感激。谢谢!

【问题讨论】:

  • 你的盐(brcypt.hashpw() 中的第二个参数)是字节编码密码(在if login_user 下)而不是bcrypt.gensalt(),取自bcrypt documentation 的任何原因?此外,您应该使用同一链接中的brcypt.checkpw(password, hashed)

标签: python flask pymongo bcrypt


【解决方案1】:

此行不遵循bcrypt的API描述:

if bcrypt.hashpw(bytes(request.form['pass'], 'utf-8'), bytes(request.form['pass'], 'utf-8')) == bytes(request.form['pass'], 'utf-8'):

文档说要这样比较:

if bcrypt.hashpw(password, hashed) == hashed:

您的环境中的hashed 在您的代码中由以下行表示:

hashpass = bcrypt.hashpw(request.form['pass'].encode('utf-8'), bcrypt.gensalt())

因此您需要以某种方式检索 hashpass,以便您的代码进行比较:

if bcrypt.hashpw(bytes(request.form['pass'], 'utf-8'), hashpass) == hashpass:

请注意,如果您使用的是more recent version (3x) of bcrypt,您应该使用:

bcrypt.checkpw(password, hashed):

【讨论】:

  • 我知道你不应该这样做,但非常感谢你!!这几天我一直在努力解决这个问题!!
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2020-02-21
  • 2022-01-25
  • 2015-09-22
  • 2014-01-31
  • 2018-07-08
  • 1970-01-01
相关资源
最近更新 更多