Public Access
feat: Authentification sécurisée fonctionnelle et correction du hash bcrypt
Build and Push Docker Image / build-and-push (push) Successful in 34s
Build and Push Docker Image / build-and-push (push) Successful in 34s
This commit is contained in:
1 parent
2d7d93bc27
commit
71d6f51ee0
6 files changed
+721
-14914
No files matched your search
+4
-12
@@ -3,9 +3,7 @@ import bcrypt
|
||||
from cryptography.fernet import Fernet
|
||||
from modules.logger import log_event
|
||||
|
||||
# 1. GÉNÉRATION DE LA CLÉ DE CRYPTAGE (À ne faire qu'une fois)
|
||||
def generer_cle_secrete():
|
||||
"""Génère une clé Fernet unique. À sauvegarder dans le .env"""
|
||||
cle = Fernet.generate_key()
|
||||
print("\n" + "="*60)
|
||||
print("⚠️ CLÉ DE CRYPTAGE GÉNÉRÉE (À CONSERVER PRÉCIEUSEMENT) ⚠️")
|
||||
@@ -21,27 +19,21 @@ def obtenir_fernet():
|
||||
raise Exception("AETHAS_ENCRYPTION_KEY introuvable dans l'environnement.")
|
||||
return Fernet(cle.encode('utf-8'))
|
||||
|
||||
# 2. CRYPTAGE DES DONNÉES SENSIBLES (Clés API des utilisateurs, CB, etc.)
|
||||
def crypter_donnee(donnee_claire):
|
||||
f = obtenir_fernet()
|
||||
return f.encrypt(donnee_claire.encode('utf-8')).decode('utf-8')
|
||||
return obtenir_fernet().encrypt(donnee_claire.encode('utf-8')).decode('utf-8')
|
||||
|
||||
def decrypter_donnee(donnee_cryptee):
|
||||
f = obtenir_fernet()
|
||||
return f.decrypt(donnee_cryptee.encode('utf-8')).decode('utf-8')
|
||||
return obtenir_fernet().decrypt(donnee_cryptee.encode('utf-8')).decode('utf-8')
|
||||
|
||||
# 3. GESTION DES MOTS DE PASSE (Hashing irréversible)
|
||||
def hasher_mot_de_passe(mot_de_passe):
|
||||
"""Hash le mot de passe avec un 'salt' unique pour la base de données."""
|
||||
return bcrypt.hashpw(mot_de_passe.encode('utf-8'), bcrypt.gensalt()).decode('utf-8')
|
||||
|
||||
def verifier_mot_de_passe(mot_de_passe_clair, hash_enregistre):
|
||||
return bcrypt.checkpw(mot_de_passe_clair.encode('utf-8'), hash_enregistre.encode('utf-8'))
|
||||
|
||||
# --- CRÉATION DE VOTRE COMPTE ADMINISTRATEUR PAR DÉFAUT ---
|
||||
# CORRECTION : Le hash est généré mathématiquement au chargement pour garantir que Xavier2026! fonctionne
|
||||
IDENTIFIANTS_ADMIN = {
|
||||
"email": "admin@mail.aethas38.duckdns.org",
|
||||
# Mot de passe par défaut : Xavier2026! (Il est hashé ici pour la sécurité du code)
|
||||
"mot_de_passe_hash": "$2b$12$R.K19pS8M5/xVd2o.3nSZeZ8GzH6J9gR/vY9x6g3Zp2vJq4vX2J0e",
|
||||
"mot_de_passe_hash": hasher_mot_de_passe("Xavier2026!"),
|
||||
"role": "Dieu tout puissant"
|
||||
}
|
||||
@@ -189,4 +189,30 @@ def render_admin_moderation_panel(utilisateur_cible):
|
||||
),
|
||||
Div(id="admin-result", style="margin-top: 15px; color: #00e5ff;"),
|
||||
cls="admin-panel"
|
||||
)
|
||||
|
||||
def render_login_page(error=None):
|
||||
error_msg = P(error, style="color: #ff4444; text-align: center; font-weight: bold;") if error else ""
|
||||
return Title("Connexion - Aethas38"), Body(
|
||||
Div(
|
||||
Img(src="/Logo/logo_aethas.svg", style="max-width: 180px; margin: 0 auto 20px; display: block;"),
|
||||
H2("Accès Restreint", style="text-align: center; color: #00e5ff;"),
|
||||
error_msg,
|
||||
Form(
|
||||
Div(
|
||||
Label("Email :", style="color: #aaa; font-size: 0.9em;"),
|
||||
Input(type="email", name="email", placeholder="admin@mail.aethas38.duckdns.org", cls="input-field", required=True),
|
||||
style="margin-bottom: 15px;"
|
||||
),
|
||||
Div(
|
||||
Label("Mot de passe :", style="color: #aaa; font-size: 0.9em;"),
|
||||
Input(type="password", name="password", placeholder="••••••••", cls="input-field", required=True),
|
||||
style="margin-bottom: 20px;"
|
||||
),
|
||||
Button("Déverrouiller le système", type="submit", cls="btn-submit", style="width: 100%;"),
|
||||
method="post", action="/login",
|
||||
),
|
||||
style="max-width: 400px; margin: 100px auto; padding: 30px; background: #1a1a1a; border-radius: 10px; border: 1px solid #333; box-shadow: 0 4px 15px rgba(0,229,255,0.1);"
|
||||
),
|
||||
style="background-color: #0d0d0d; color: #fff; font-family: monospace; height: 100vh; display: flex; align-items: center; justify-content: center;"
|
||||
)
|
||||
Reference in new issue
Block a user