rewrite PasswordFactor to use backends setting instead of trying all backends
This commit is contained in:
		@ -1,8 +1,10 @@
 | 
			
		||||
"""passbook multi-factor authentication engine"""
 | 
			
		||||
from inspect import Signature
 | 
			
		||||
from logging import getLogger
 | 
			
		||||
 | 
			
		||||
from django.contrib import messages
 | 
			
		||||
from django.contrib.auth import authenticate
 | 
			
		||||
from django.contrib.auth import _clean_credentials
 | 
			
		||||
from django.contrib.auth.signals import user_login_failed
 | 
			
		||||
from django.core.exceptions import PermissionDenied
 | 
			
		||||
from django.forms.utils import ErrorList
 | 
			
		||||
from django.shortcuts import redirect, reverse
 | 
			
		||||
@ -15,10 +17,40 @@ from passbook.core.forms.authentication import PasswordFactorForm
 | 
			
		||||
from passbook.core.models import Nonce
 | 
			
		||||
from passbook.core.tasks import send_email
 | 
			
		||||
from passbook.lib.config import CONFIG
 | 
			
		||||
from passbook.lib.utils.reflection import path_to_class
 | 
			
		||||
 | 
			
		||||
LOGGER = getLogger(__name__)
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
def authenticate(request, backends, **credentials):
 | 
			
		||||
    """If the given credentials are valid, return a User object.
 | 
			
		||||
    Customized version of django's authenticate, which accepts a list of backends"""
 | 
			
		||||
    for backend_path in backends:
 | 
			
		||||
        backend = path_to_class(backend_path)()
 | 
			
		||||
        try:
 | 
			
		||||
            signature = Signature.from_callable(backend.authenticate)
 | 
			
		||||
            signature.bind(request, **credentials)
 | 
			
		||||
        except TypeError:
 | 
			
		||||
            LOGGER.debug("Backend %s doesn't accept our arguments", backend)
 | 
			
		||||
            # This backend doesn't accept these credentials as arguments. Try the next one.
 | 
			
		||||
            continue
 | 
			
		||||
        LOGGER.debug('Attempting authentication with %s...', backend)
 | 
			
		||||
        try:
 | 
			
		||||
            user = backend.authenticate(request, **credentials)
 | 
			
		||||
        except PermissionDenied:
 | 
			
		||||
            LOGGER.debug('Backend %r threw PermissionDenied', backend)
 | 
			
		||||
            # This backend says to stop in our tracks - this user should not be allowed in at all.
 | 
			
		||||
            break
 | 
			
		||||
        if user is None:
 | 
			
		||||
            continue
 | 
			
		||||
        # Annotate the user object with the path of the backend.
 | 
			
		||||
        user.backend = backend_path
 | 
			
		||||
        return user
 | 
			
		||||
 | 
			
		||||
    # The credentials supplied are invalid to all backends, fire signal
 | 
			
		||||
    user_login_failed.send(sender=__name__, credentials=_clean_credentials(
 | 
			
		||||
        credentials), request=request)
 | 
			
		||||
 | 
			
		||||
class PasswordFactor(FormView, AuthenticationFactor):
 | 
			
		||||
    """Authentication factor which authenticates against django's AuthBackend"""
 | 
			
		||||
 | 
			
		||||
@ -57,7 +89,7 @@ class PasswordFactor(FormView, AuthenticationFactor):
 | 
			
		||||
        for uid_field in uid_fields:
 | 
			
		||||
            kwargs[uid_field] = getattr(self.authenticator.pending_user, uid_field)
 | 
			
		||||
        try:
 | 
			
		||||
            user = authenticate(self.request, **kwargs)
 | 
			
		||||
            user = authenticate(self.request, self.authenticator.current_factor.backends, **kwargs)
 | 
			
		||||
            if user:
 | 
			
		||||
                # User instance returned from authenticate() has .backend property set
 | 
			
		||||
                self.authenticator.pending_user = user
 | 
			
		||||
 | 
			
		||||
		Reference in New Issue
	
	Block a user