English 中文(简体)
如何使用弗拉斯克校验饼干完整性?
原标题:How to verify cookie integrity using Flask?

使用瓶子时, 我试图验证一个 cookie 没有被篡改 。 现在, 如果我改变 cookie 值, 它只会丢弃一个错误, 但是我要检查代码是_ valid( session[ user_ id] ), 如果不是的话, 重定向/ 重置 。

在#pocoo的某人说:

  • actually, you could call SecureCookie.unserialize and catch the exception
  • ah, it fails silently
  • looks like you have to try unserializing it and check if you get an empty object from it

有没有人能进一步解释一下这个代码会是什么样子?

最佳回答

https://github.com/mitsuhiko/werkzeug/blob/master/werkzeug/werkzeug/contrib/contrib/securecookie.py#L265" rel=“nofollow'>https://github.com/mitsuhiko/werkzeug/blob/master/werkzeug/contrib/securcookie.py#L265

safe_str_cmp( client_hash, mac.digest ())) 正在执行检查, 如果饼干被篡改, 检查将会失败 。

取决于你到底想抓住什么 你可以跳到不同的地方

data = request.cookies.get("session")
cookie = werkzeug.contrib.securecookie.SecureCookie.unserialize(data, secret_key)

如果存在 data cookie 没有包含任何数据, 则无序列化失败。 许多原因之一是 safe_str_ cmp () (在 unsergize () 调用) 返回 False 。

问题回答

暂无回答




相关问题
Can Django models use MySQL functions?

Is there a way to force Django models to pass a field to a MySQL function every time the model data is read or loaded? To clarify what I mean in SQL, I want the Django model to produce something like ...

An enterprise scheduler for python (like quartz)

I am looking for an enterprise tasks scheduler for python, like quartz is for Java. Requirements: Persistent: if the process restarts or the machine restarts, then all the jobs must stay there and ...

How to remove unique, then duplicate dictionaries in a list?

Given the following list that contains some duplicate and some unique dictionaries, what is the best method to remove unique dictionaries first, then reduce the duplicate dictionaries to single ...

What is suggested seed value to use with random.seed()?

Simple enough question: I m using python random module to generate random integers. I want to know what is the suggested value to use with the random.seed() function? Currently I am letting this ...

How can I make the PyDev editor selectively ignore errors?

I m using PyDev under Eclipse to write some Jython code. I ve got numerous instances where I need to do something like this: import com.work.project.component.client.Interface.ISubInterface as ...

How do I profile `paster serve` s startup time?

Python s paster serve app.ini is taking longer than I would like to be ready for the first request. I know how to profile requests with middleware, but how do I profile the initialization time? I ...

Pragmatically adding give-aways/freebies to an online store

Our business currently has an online store and recently we ve been offering free specials to our customers. Right now, we simply display the special and give the buyer a notice stating we will add the ...

Converting Dictionary to List? [duplicate]

I m trying to convert a Python dictionary into a Python list, in order to perform some calculations. #My dictionary dict = {} dict[ Capital ]="London" dict[ Food ]="Fish&Chips" dict[ 2012 ]="...

热门标签