GithubHelp home page GithubHelp logo

qup42 / django-aletheia Goto Github PK

View Code? Open in Web Editor NEW
0.0 1.0 1.0 55 KB

WebAuthN support for Django. Provided with a custom AuthBackend.

License: BSD 3-Clause "New" or "Revised" License

Python 77.03% HTML 22.97%
authentication django webauthn

django-aletheia's Issues

Information leak in auth_backend

expired keys are rejected befor checked for legitamacy.
This can be abused for checking if a user has loged in in the last 6 months.

if credential.user.webauthnuser.last_login_with_password + relativedelta(months=6) < timezone.now():
messages.error(request, f"Authentication with WebAuthN failed. Please login with password.",
fail_silently=True)
return None
try:
authentication_verification = verify_authentication_response(
credential=AuthenticationCredential.parse_raw(data),
expected_challenge=challenge.encode("utf-8"),
expected_rp_id=settings.RELYING_PARTY_ID,
expected_origin=settings.EXPECTED_ORIGIN,
require_user_verification=False,
credential_current_sign_count=credential.sign_count,
credential_public_key=base64decode(credential.public_key)
)
except InvalidAuthenticationResponse:
# TODO: give concrete feedback about why the authentication failed?
messages.error(request, f"Authentication failed", fail_silently=True)
return None

Add Manage Site

This should allow to view all registered keys and delete registered keys.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.