Skip to content

Commit bfdb927

Browse files
committed
feature: Auth service, Auth DB init script
0 parents  commit bfdb927

File tree

3 files changed

+257
-0
lines changed

3 files changed

+257
-0
lines changed

.gitignore

+160
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,160 @@
1+
# Byte-compiled / optimized / DLL files
2+
__pycache__/
3+
*.py[cod]
4+
*$py.class
5+
6+
# C extensions
7+
*.so
8+
9+
# Distribution / packaging
10+
.Python
11+
build/
12+
develop-eggs/
13+
dist/
14+
downloads/
15+
eggs/
16+
.eggs/
17+
lib/
18+
lib64/
19+
parts/
20+
sdist/
21+
var/
22+
wheels/
23+
share/python-wheels/
24+
*.egg-info/
25+
.installed.cfg
26+
*.egg
27+
MANIFEST
28+
29+
# PyInstaller
30+
# Usually these files are written by a python script from a template
31+
# before PyInstaller builds the exe, so as to inject date/other infos into it.
32+
*.manifest
33+
*.spec
34+
35+
# Installer logs
36+
pip-log.txt
37+
pip-delete-this-directory.txt
38+
39+
# Unit test / coverage reports
40+
htmlcov/
41+
.tox/
42+
.nox/
43+
.coverage
44+
.coverage.*
45+
.cache
46+
nosetests.xml
47+
coverage.xml
48+
*.cover
49+
*.py,cover
50+
.hypothesis/
51+
.pytest_cache/
52+
cover/
53+
54+
# Translations
55+
*.mo
56+
*.pot
57+
58+
# Django stuff:
59+
*.log
60+
local_settings.py
61+
db.sqlite3
62+
db.sqlite3-journal
63+
64+
# Flask stuff:
65+
instance/
66+
.webassets-cache
67+
68+
# Scrapy stuff:
69+
.scrapy
70+
71+
# Sphinx documentation
72+
docs/_build/
73+
74+
# PyBuilder
75+
.pybuilder/
76+
target/
77+
78+
# Jupyter Notebook
79+
.ipynb_checkpoints
80+
81+
# IPython
82+
profile_default/
83+
ipython_config.py
84+
85+
# pyenv
86+
# For a library or package, you might want to ignore these files since the code is
87+
# intended to run in multiple environments; otherwise, check them in:
88+
# .python-version
89+
90+
# pipenv
91+
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
92+
# However, in case of collaboration, if having platform-specific dependencies or dependencies
93+
# having no cross-platform support, pipenv may install dependencies that don't work, or not
94+
# install all needed dependencies.
95+
#Pipfile.lock
96+
97+
# poetry
98+
# Similar to Pipfile.lock, it is generally recommended to include poetry.lock in version control.
99+
# This is especially recommended for binary packages to ensure reproducibility, and is more
100+
# commonly ignored for libraries.
101+
# https://python-poetry.org/docs/basic-usage/#commit-your-poetrylock-file-to-version-control
102+
#poetry.lock
103+
104+
# pdm
105+
# Similar to Pipfile.lock, it is generally recommended to include pdm.lock in version control.
106+
#pdm.lock
107+
# pdm stores project-wide configurations in .pdm.toml, but it is recommended to not include it
108+
# in version control.
109+
# https://pdm.fming.dev/#use-with-ide
110+
.pdm.toml
111+
112+
# PEP 582; used by e.g. github.com/David-OConnor/pyflow and github.com/pdm-project/pdm
113+
__pypackages__/
114+
115+
# Celery stuff
116+
celerybeat-schedule
117+
celerybeat.pid
118+
119+
# SageMath parsed files
120+
*.sage.py
121+
122+
# Environments
123+
.env
124+
.venv
125+
env/
126+
venv/
127+
ENV/
128+
env.bak/
129+
venv.bak/
130+
131+
# Spyder project settings
132+
.spyderproject
133+
.spyproject
134+
135+
# Rope project settings
136+
.ropeproject
137+
138+
# mkdocs documentation
139+
/site
140+
141+
# mypy
142+
.mypy_cache/
143+
.dmypy.json
144+
dmypy.json
145+
146+
# Pyre type checker
147+
.pyre/
148+
149+
# pytype static type analyzer
150+
.pytype/
151+
152+
# Cython debug symbols
153+
cython_debug/
154+
155+
# PyCharm
156+
# JetBrains specific template is maintained in a separate JetBrains.gitignore that can
157+
# be found at https://github.com/github/gitignore/blob/main/Global/JetBrains.gitignore
158+
# and can be added to the global gitignore or merged into this file. For a more nuclear
159+
# option (not recommended) you can uncomment the following to ignore the entire idea folder.
160+
#.idea/

python/src/auth/init.sql

+20
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
CREATE USER 'auth_user'@'localhost' IDENTIFIED BY 'Auth123';
2+
3+
CREATE DATABASE auth;
4+
5+
GRANT ALL PRIVILEGES ON auth.* TO 'auth_user'@'localhost';
6+
7+
USE auth;
8+
9+
CREATE TABLE user (
10+
id INT NOT NULL AUTO_INCREMENT PRIMARY KEY,
11+
email VARCHAR(255) NOT NULL UNIQUE,
12+
password VARCHAR(255) NOT NULL
13+
);
14+
15+
INSERT INTO user (email, password) VALUES ('polevych@gmail.com', 'Admin123');
16+
17+
18+
19+
20+

python/src/auth/server.py

+77
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,77 @@
1+
import jwt
2+
import datetime
3+
import os
4+
from flask import Flask, request
5+
from flask_mysqldb import MySQL
6+
from flask_bcrypt import Bcrypt
7+
8+
server = Flask(__name__)
9+
mysql = MySQL(server)
10+
bcrypt = Bcrypt(server)
11+
12+
# config
13+
server.config["MYSQL_HOST"] = os.environ.get("MYSQL_HOST")
14+
server.config["MYSQL_USER"] = os.environ.get("MYSQL_USER")
15+
server.config["MYSQL_PASSWORD"] = os.environ.get("MYSQL_PASSWORD")
16+
server.config["MYSQL_DB"] = os.environ.get("MYSQL_DB")
17+
server.config["MYSQL_PORT"] = int(os.environ.get("MYSQL_PORT"))
18+
19+
@server.route("/login", methods=["POST"])
20+
def login():
21+
auth = request.authorization
22+
if not auth:
23+
return "no credentials provided", 401
24+
25+
# check db for username and hashed password
26+
cur = mysql.connection.cursor()
27+
res = cur.execute(
28+
"SELECT email, password FROM user WHERE email=%s", (auth.username,)
29+
)
30+
31+
if res > 0:
32+
user_row = cur.fetchone()
33+
email = user_row[0]
34+
hashed_password = user_row[1]
35+
36+
if auth.username != email or not bcrypt.check_password_hash(hashed_password, auth.password):
37+
return "invalid credentials", 401
38+
else:
39+
return createJWT(auth.username, os.environ.get("JWT_SECRET"), True)
40+
else:
41+
return "invalid credentials", 401
42+
43+
@server.route("/validate", methods=["POST"])
44+
def validate():
45+
encoded_jwt = request.headers.get("Authorization")
46+
47+
if not encoded_jwt:
48+
return "missing credentials", 401
49+
50+
encoded_jwt = encoded_jwt.split(" ")[1]
51+
52+
try:
53+
decoded = jwt.decode(
54+
encoded_jwt, os.environ.get("JWT_SECRET"), algorithms=["HS256"]
55+
)
56+
except jwt.ExpiredSignatureError:
57+
return "token has expired", 401
58+
except jwt.InvalidTokenError:
59+
return "invalid token", 401
60+
61+
return decoded, 200
62+
63+
def createJWT(username, secret, authz):
64+
return jwt.encode(
65+
{
66+
"username": username,
67+
"exp": datetime.datetime.now(tz=datetime.timezone.utc)
68+
+ datetime.timedelta(days=1),
69+
"iat": datetime.datetime.utcnow(),
70+
"admin": authz,
71+
},
72+
secret,
73+
algorithm="HS256",
74+
)
75+
76+
if __name__ == "__main__":
77+
server.run(host="0.0.0.0", port=5000)

0 commit comments

Comments
 (0)