refac
This commit is contained in:
@@ -8,6 +8,7 @@ from typing import Optional
|
||||
|
||||
from open_webui.internal.db import Base, JSONField, get_async_db_context
|
||||
from open_webui.models.users import User, UserModel, UserProfileImageResponse, Users
|
||||
from open_webui.utils.auth import PLACEHOLDER_HASH
|
||||
from open_webui.utils.validate import validate_profile_image_url
|
||||
from pydantic import BaseModel, field_validator
|
||||
from sqlalchemy import Boolean, Column, String, Text, delete, select, update
|
||||
@@ -142,11 +143,13 @@ class AuthsTable:
|
||||
log.info('authenticate_user: %s', email)
|
||||
resolved = await Users.get_user_by_email(email, db=db)
|
||||
if not resolved:
|
||||
verify_password(PLACEHOLDER_HASH)
|
||||
return
|
||||
# load the credential row and verify the password hash
|
||||
async with get_async_db_context(db) as session:
|
||||
credential = await session.get(Auth, resolved.id)
|
||||
if not credential or not credential.active:
|
||||
verify_password(PLACEHOLDER_HASH)
|
||||
return
|
||||
if not verify_password(credential.password):
|
||||
return
|
||||
|
||||
@@ -162,6 +162,12 @@ def get_password_hash(password: str) -> str:
|
||||
return bcrypt.hashpw(password.encode('utf-8'), bcrypt.gensalt()).decode('utf-8')
|
||||
|
||||
|
||||
# Pre-computed hash verified on signin paths that lack a real credential
|
||||
# (unknown user, inactive account) so response timing cannot reveal
|
||||
# whether an account exists (CWE-208).
|
||||
PLACEHOLDER_HASH = get_password_hash('placeholder')
|
||||
|
||||
|
||||
def validate_password(password: str) -> bool:
|
||||
# The password passed to bcrypt must be 72 bytes or fewer. If it is longer, it will be truncated before hashing.
|
||||
if len(password.encode('utf-8')) > 72:
|
||||
|
||||
Reference in New Issue
Block a user