数据库模型
# pip install passlib from passlib.apps import custom_app_context as pwd_context class Shop_list(db.Model): __tablename__ = 'shop_list' userName = db.Column(db.BigInteger,primary_key = True) #手机号 passWord = db.Column(db.Text,nullable=False) def hash_password(self, password): #给密码加密方法 self.passWord = pwd_context.encrypt(password) def verify_password(self, password): #验证密码方法 return pwd_context.verify(password, self.passWord)
注册接口
@app.route('/api/v1/admin/register',methods=['POST'])
def register():
username = request.form.get('username')
password = request.form.get('password')
save = Shop_list(userName=username)
save.hash_password(password) #调用密码加密方法
db.session.add(save)
db.session.commit()
return 'success'登录接口
@app.route('/api/v1/admin/login',methods=['POST'])
def login():
username = request.form.get('username')
password = request.form.get('password')
obj = Shop_list.query.filter_by(userName=username).first()
if not obj:
return res_json(201,'','未找到该用户')
if obj.verify_password(password):
token = generate_token(username)
return res_json(200,{'token':token},'登录成功')
else:
return res_json(201,'','密码错误')重头戏:token的生成与验证方法
import time
import base64
import hmac
#生成token 入参:用户id
def generate_token(key, expire=3600):
ts_str = str(time.time() + expire)
ts_byte = ts_str.encode("utf-8")
sha1_tshexstr = hmac.new(key.encode("utf-8"),ts_byte,'sha1').hexdigest()
token = ts_str+':'+sha1_tshexstr
b64_token = base64.urlsafe_b64encode(token.encode("utf-8"))
return b64_token.decode("utf-8")
#验证token 入参:用户id 和 token
def certify_token(key, token):
token_str = base64.urlsafe_b64decode(token).decode('utf-8')
token_list = token_str.split(':')
if len(token_list) != 2:
return False
ts_str = token_list[0]
if float(ts_str) < time.time():
# token expired
return False
known_sha1_tsstr = token_list[1]
sha1 = hmac.new(key.encode("utf-8"),ts_str.encode('utf-8'),'sha1')
calc_sha1_tsstr = sha1.hexdigest()
if calc_sha1_tsstr != known_sha1_tsstr:
# token certification failed
return False
# token certification success
return True