Add verified camera settings, family version recovery and account self service
This commit is contained in:
+26
@@ -4,11 +4,13 @@ import hmac
|
||||
import json
|
||||
import re
|
||||
import secrets
|
||||
import time
|
||||
|
||||
|
||||
class Accounts:
|
||||
def __init__(self, app):
|
||||
self.a = app
|
||||
self.password_attempts = {}
|
||||
|
||||
def initialize(self):
|
||||
a = self.a
|
||||
@@ -99,6 +101,30 @@ class Accounts:
|
||||
a.audit('更新账号' if old else '建立账号', username)
|
||||
return self.public(user)
|
||||
|
||||
def change_password(self, data, actor):
|
||||
a = self.a
|
||||
with a.LOCK:
|
||||
current = a.get_object('users', actor['id'])
|
||||
if not current or current['disabled']:
|
||||
raise a.Problem('请重新登录', 401)
|
||||
now = time.time()
|
||||
self.password_attempts = {k: v for k, v in self.password_attempts.items() if v[1] > now}
|
||||
count, expiry = self.password_attempts.get(current['id'], (0, now + 900))
|
||||
if count >= 8:
|
||||
raise a.Problem('当前密码尝试次数过多,请 15 分钟后重试', 429)
|
||||
if not self.verify(current['username'], data.get('currentPassword')):
|
||||
self.password_attempts[current['id']] = (count + 1, expiry)
|
||||
raise a.Problem('当前密码不正确', 403)
|
||||
if data.get('newPassword') == data.get('currentPassword'):
|
||||
raise a.Problem('新密码不能与当前密码相同')
|
||||
credentials = self.password(data.get('newPassword'))
|
||||
with a.DB:
|
||||
a.DB.execute('UPDATE users SET body=? WHERE id=?', (json.dumps(dict(current, **credentials)), current['id']))
|
||||
a.DB.execute('DELETE FROM sessions WHERE user_id=?', (current['id'],))
|
||||
self.password_attempts.pop(current['id'], None)
|
||||
a.audit('本人修改密码', current['username'])
|
||||
return {'ok': True}
|
||||
|
||||
def camera(self, user, camera):
|
||||
if not camera:
|
||||
raise self.a.Problem('摄像头不存在', 404)
|
||||
|
||||
Reference in New Issue
Block a user