本文整理汇总了Python中empower.main.RUNTIME.check_permission方法的典型用法代码示例。如果您正苦于以下问题:Python RUNTIME.check_permission方法的具体用法?Python RUNTIME.check_permission怎么用?Python RUNTIME.check_permission使用的例子?那么恭喜您, 这里精选的方法代码示例或许可以为您提供帮助。您也可以进一步了解该方法所在类empower.main.RUNTIME
的用法示例。
在下文中一共展示了RUNTIME.check_permission方法的2个代码示例,这些例子默认根据受欢迎程度排序。您可以为喜欢或者感觉有用的代码点赞,您的评价将有助于系统推荐出更棒的Python代码示例。
示例1: post
# 需要导入模块: from empower.main import RUNTIME [as 别名]
# 或者: from empower.main.RUNTIME import check_permission [as 别名]
def post(self):
username = self.get_argument("username", "")
password = self.get_argument("password", "")
if RUNTIME.check_permission(username, password):
self.set_secure_cookie("user", username)
self.redirect(self.get_argument("next", "/"))
else:
error_msg = "Login incorrect."
self.redirect("/auth/login/" +
"?error=" +
tornado.escape.url_escape(error_msg))
示例2: prepare
# 需要导入模块: from empower.main import RUNTIME [as 别名]
# 或者: from empower.main.RUNTIME import check_permission [as 别名]
def prepare(self):
"""Prepare to handler reply."""
self.set_header('Content-Type', 'application/json')
if not self.RIGHTS[self.request.method]:
return
auth_header = self.request.headers.get('Authorization')
if auth_header is None or not auth_header.startswith('Basic '):
self.set_header('WWW-Authenticate', 'Basic realm=Restricted')
self.send_error(401)
return
auth_bytes = bytes(auth_header[6:], 'utf-8')
auth_decoded = base64.b64decode(auth_bytes).decode()
username, password = auth_decoded.split(':', 2)
# account does not exists
if not RUNTIME.check_permission(username, password):
self.send_error(401)
return
self.account = RUNTIME.get_account(username)
if self.account.role in self.RIGHTS[self.request.method]:
if self.account.role == ROLE_ADMIN:
return
if self.request.uri.startswith("/api/v1/accounts"):
pattern = re.compile("/api/v1/accounts/([a-zA-Z0-9:-]*)/?")
match = pattern.match(self.request.uri)
if match and match.group(1):
if match.group(1) in RUNTIME.accounts:
account = RUNTIME.accounts[match.group(1)]
if self.account.username == account.username:
return
else:
self.send_error(401)
return
return
if self.request.uri.startswith("/api/v1/pending"):
pattern = re.compile("/api/v1/pending/([a-zA-Z0-9-]*)/?")
match = pattern.match(self.request.uri)
if match and match.group(1):
try:
tenant_id = UUID(match.group(1))
except ValueError:
self.send_error(400)
return
pending = RUNTIME.load_pending_tenant(tenant_id)
if pending:
if self.account.username == pending.owner:
return
self.send_error(401)
return
return
if self.request.uri.startswith("/api/v1/tenants"):
pattern = re.compile("/api/v1/tenants/([a-zA-Z0-9-]*)/?")
match = pattern.match(self.request.uri)
if match and match.group(1):
tenant_id = UUID(match.group(1))
if tenant_id in RUNTIME.tenants:
tenant = RUNTIME.tenants[tenant_id]
if self.account.username == tenant.owner:
return
self.send_error(401)
return
return
self.send_error(401)
return