sys_user_data.py 2.9 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788
  1. #!/usr/bin/env python3
  2. # -*- coding: utf-8 -*-
  3. from . import mpfun
  4. from models import *
  5. from sqlalchemy.orm import Session
  6. from database import get_local_db
  7. # 系统用户表
  8. # 加密和HMAC签名
  9. def sign_row(db: Session, row: SysUser) -> None:
  10. if row.sign != '':
  11. return
  12. user_id = str(row.user_id) # 用户ID
  13. user_name = mpfun.enc_data(row.user_name) # 用户账号
  14. password = mpfun.enc_data(row.password) # 密码
  15. nick_name = mpfun.base64_data(row.nick_name) # 用户昵称
  16. dept_id = str(row.dept_id) # 部门ID
  17. dept_name = mpfun.base64_data(row.dept_name) # 部门名称
  18. email = mpfun.enc_data(row.email) # 电子邮箱
  19. phonenumber = mpfun.enc_data(row.phonenumber) # 手机号码
  20. status = str(row.status) # 用户状态
  21. del_flag = row.del_flag # 是否已删除
  22. yzy_account = mpfun.enc_data(row.yzy_account) # 粤政易账号
  23. sign_data = ",".join([user_id, user_name, password, nick_name, dept_id, dept_name, email, phonenumber, status, del_flag, yzy_account])
  24. sign_hmac = mpfun.sign_data(sign_data)
  25. # print('sign_tbl_user sign_data:', sign_data)
  26. # print('sign_tbl_user sign_hmac:', sign_hmac)
  27. row.user_name = user_name
  28. row.password = password
  29. row.email = email
  30. row.phonenumber = phonenumber
  31. row.yzy_account = yzy_account
  32. row.sign = sign_hmac
  33. db.commit()
  34. # 比较字段合并字符串是否和MAC值匹配上,调用密码服务器[验证HMAC]接口
  35. def sign_valid_row(row: SysUser) -> bool:
  36. return True
  37. if row.sign == '':
  38. return True
  39. # 关键字段合并字符串
  40. sign_data = get_sign_str(row)
  41. # print('sys_user sign_data:', sign_data)
  42. # 原HMACSM3数值
  43. sign_hmac = row.sign
  44. # print('sign_hmac:', sign_hmac)
  45. return mpfun.hmac_verify(sign_data, sign_hmac)
  46. # 生成待签名的字符串
  47. def get_sign_str(row: SysUser) -> str:
  48. user_id = str(row.user_id) # 用户ID
  49. user_name = row.user_name # 用户账号
  50. password = row.password # 密码
  51. nick_name = mpfun.base64_data(row.nick_name) # 用户昵称
  52. dept_id = str(row.dept_id) # 部门ID
  53. dept_name = mpfun.base64_data(row.dept_name) # 部门名称
  54. email = row.email # 电子邮箱
  55. phonenumber = row.phonenumber # 手机号码
  56. status = str(row.status) # 用户状态
  57. del_flag = row.del_flag # 是否已删除
  58. yzy_account = row.yzy_account # 粤政易账号
  59. # 关键字段合并字符串
  60. sign_data = ",".join([user_id, user_name, password, nick_name, dept_id, dept_name, email, phonenumber, status, del_flag, yzy_account])
  61. return sign_data
  62. # 生成HAMC签名值
  63. def get_sign_hmac(row: SysUser) -> str:
  64. sign_data = get_sign_str(row)
  65. return mpfun.sign_data(sign_data)
  66. # 对所有数据进行签名
  67. def sign_table():
  68. print('sign_sys_user table =====>>>')
  69. with get_local_db() as db:
  70. rows = db.query(SysUser).filter(SysUser.sign == '').all()
  71. for row in rows:
  72. sign_row(db, row)