1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677 |
- #!/usr/bin/env python3
- # -*- coding: utf-8 -*-
- from . import mpfun
- from models import *
- from sqlalchemy.orm import Session
- # 系统用户表
- # 加密和HMAC签名
- def sign_row(db: Session, row: SysUser) -> None:
- if row.sign != '':
- return
-
- user_id = str(row.user_id) # 用户ID
- user_name = mpfun.enc_data(row.user_name) # 用户账号
- password = mpfun.enc_data(row.password) # 密码
- nick_name = mpfun.base64_data(row.nick_name) # 用户昵称
- dept_id = str(row.dept_id) # 部门ID
- dept_name = mpfun.base64_data(row.dept_name) # 部门名称
- email = mpfun.enc_data(row.email) # 电子邮箱
- phonenumber = mpfun.enc_data(row.phonenumber) # 手机号码
- status = str(row.status) # 用户状态
- del_flag = row.del_flag # 是否已删除
- yzy_account = mpfun.enc_data(row.yzy_account) # 粤政易账号
- sign_data = ",".join([user_id, user_name, password, nick_name, dept_id, dept_name, email, phonenumber, status, del_flag, yzy_account])
- sign_hmac = mpfun.sign_data(sign_data)
- # print('sign_tbl_user sign_data:', sign_data)
- # print('sign_tbl_user sign_hmac:', sign_hmac)
- row.user_name = user_name
- row.password = password
- row.email = email
- row.phonenumber = phonenumber
- row.yzy_account = yzy_account
- row.sign = sign_hmac
-
- db.commit()
- # 比较字段合并字符串是否和MAC值匹配上,调用密码服务器[验证HMAC]接口
- def sign_valid_row(row: SysUser) -> bool:
- if row.sign == '':
- return True
- # 关键字段合并字符串
- sign_data = get_sign_str(row)
- # print('sys_user sign_data:', sign_data)
-
- # 原HMACSM3数值
- sign_hmac = row.sign
- # print('sign_hmac:', sign_hmac)
- return mpfun.hmac_verify(sign_data, sign_hmac)
- # 生成待签名的字符串
- def get_sign_str(row: SysUser) -> str:
- user_id = str(row.user_id) # 用户ID
- user_name = row.user_name # 用户账号
- password = row.password # 密码
- nick_name = mpfun.base64_data(row.nick_name) # 用户昵称
- dept_id = str(row.dept_id) # 部门ID
- dept_name = mpfun.base64_data(row.dept_name) # 部门名称
- email = row.email # 电子邮箱
- phonenumber = row.phonenumber # 手机号码
- status = str(row.status) # 用户状态
- del_flag = row.del_flag # 是否已删除
- yzy_account = row.yzy_account # 粤政易账号
- # 关键字段合并字符串
- sign_data = ",".join([user_id, user_name, password, nick_name, dept_id, dept_name, email, phonenumber, status, del_flag, yzy_account])
- return sign_data
- # 生成HAMC签名值
- def get_sign_hmac(row: SysUser) -> str:
- sign_data = get_sign_str(row)
- return mpfun.sign_data(sign_data)
|