fix server auth
This commit is contained in:
parent
9b9197be0e
commit
1b3af70082
@ -66,7 +66,7 @@ def protected(wrapped):
|
||||
)
|
||||
@validate(json=LoginRequest)
|
||||
async def login(request):
|
||||
if pbkdf2_sha256(request.json['password']) != api_auth.get(request.json['username']):
|
||||
if not pbkdf2_sha256(10000, salt=b'salt').verify(request.json['password'], api_auth.get(request.json['username'])):
|
||||
return {'status': 'error', 'message': 'Invalid username or password'}
|
||||
return {
|
||||
'token': jwt.encode({}, api_secret, algorithm='HS256'),
|
||||
|
Loading…
Reference in New Issue
Block a user