aio-libs / aio-libs/aiosmtpd

Example authenticated replayer is not working; Solved

Abierto
#390 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Python
Estrellas
373
Forks
105
Merge medio
4 min
PR fusionados (30 d)
2

Descripción

Dear aiosmtpd people!
Thank you for your work!

The "authenticated replayer" example has two bugs:

* The username and password have to be decoded to utf-8 since they may be bytes (dependent of the client).
* Argon2 hashes cannot simply be compared, they have to be verified.

Here the fixed code.

```
class Authenticator:
def __init__(self, auth_database):
self.auth_db = Path(auth_database)
self.ph = PasswordHasher()

def __call__(self, server, session, envelope, mechanism, auth_data):
fail_nothandled = AuthResult(success=False, handled=False)
if mechanism not in ("LOGIN", "PLAIN"):
return fail_nothandled
if not isinstance(auth_data, LoginPassword):
return fail_nothandled
username = auth_data.login.decode()
password = auth_data.password.decode()
conn = sqlite3.connect(self.auth_db)
curs = conn.execute(
"SELECT hashpass FROM userauth WHERE username=?", (username,)
)
hash_db = curs.fetchone()
conn.close()
if not hash_db:
return fail_nothandled
if not self.ph.verify(hash_db[0], password):
return fail_nothandled
return AuthResult(success=True)
```

Cheers,
Volker

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.