main.py 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201
  1. # fastapi
  2. from fastapi import FastAPI, Request, Response, HTTPException, status, Depends
  3. from fastapi import templating
  4. from fastapi.templating import Jinja2Templates
  5. from fastapi.responses import HTMLResponse, RedirectResponse, JSONResponse
  6. from fastapi.middleware.cors import CORSMiddleware
  7. # static file
  8. from fastapi.staticfiles import StaticFiles
  9. # fastapi view function parameters
  10. from typing import List, Optional
  11. # path
  12. import os
  13. # time
  14. # import datetime
  15. from datetime import timedelta, datetime
  16. # db
  17. import dataset
  18. from passlib import context
  19. import models
  20. # authorize
  21. from passlib.context import CryptContext
  22. pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto")
  23. from jose import JWTError, jwt
  24. from fastapi_jwt_auth import AuthJWT
  25. from fastapi_jwt_auth.exceptions import AuthJWTException
  26. from fastapi.security import OAuth2AuthorizationCodeBearer, OAuth2PasswordRequestForm
  27. # app
  28. app = FastAPI()
  29. app.add_middleware(
  30. CORSMiddleware,
  31. allow_origins=["*"],
  32. allow_credentials=True,
  33. allow_methods=["*"],
  34. allow_headers=["*"],
  35. )
  36. SECRET_KEY = "df2f77bd544240801a048bd4293afd8eeb7fff3cb7050e42c791db4b83ebadcd"
  37. ALGORITHM = "HS256"
  38. ACCESS_TOKEN_EXPIRE_MINUTES = 3000
  39. pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto")
  40. #
  41. app.mount(path='/templates', app=StaticFiles(directory='templates'), name='templates')
  42. app.mount(path='/static', app=StaticFiles(directory='static'), name='static ')
  43. #
  44. templates = Jinja2Templates(directory='templates')
  45. # view
  46. @app.get('/', response_class=HTMLResponse)
  47. async def index(request: Request):
  48. print(request)
  49. return templates.TemplateResponse(name='index.html', context={'request': request})
  50. @app.get('/login', response_class=HTMLResponse)
  51. async def login(request: Request):
  52. return templates.TemplateResponse(name='login.html', context={'request': request})
  53. @app.post("/login")
  54. async def login_for_access_token(request: Request, form_data: OAuth2PasswordRequestForm = Depends(), Authorize: AuthJWT = Depends()):
  55. db = dataset.connect('mysql://choozmo:pAssw0rd@db.ptt.cx:3306/aaron_testdb?charset=utf8mb4')
  56. user = authenticate_user(form_data.username, form_data.password)
  57. if not user:
  58. raise HTTPException(
  59. status_code=status.HTTP_401_UNAUTHORIZED,
  60. detail="Incorrect username or password",
  61. headers={"WWW-Authenticate": "Bearer"},
  62. )
  63. access_token_expires = timedelta(minutes=ACCESS_TOKEN_EXPIRE_MINUTES)
  64. access_token = create_access_token(
  65. data={"sub": user.username}, expires_delta=access_token_expires
  66. )
  67. table = db['users']
  68. user.token = access_token
  69. table.update(dict(user), ['username'])
  70. access_token = Authorize.create_access_token(subject=user.username)
  71. refresh_token = Authorize.create_refresh_token(subject=user.username)
  72. Authorize.set_access_cookies(access_token)
  73. Authorize.set_refresh_cookies(refresh_token)
  74. #return templates.TemplateResponse("index.html", {"request": request, "msg": 'Login'})
  75. return {"access_token": access_token, "token_type": "bearer"}
  76. @app.get('/register', response_class=HTMLResponse)
  77. async def login(request: Request):
  78. return templates.TemplateResponse(name='register.html', context={'request': request})
  79. @app.post('/register')
  80. async def register(request: Request, form_data: OAuth2PasswordRequestForm = Depends()):
  81. user = models.User(**await request.form())
  82. print(form_data.username, form_data.password, user)
  83. # 密碼加密
  84. user.password = get_password_hash(user.password)
  85. # 存入DB
  86. db = dataset.connect('mysql://choozmo:pAssw0rd@db.ptt.cx:3306/aaron_testdb?charset=utf8mb4')
  87. user_table = db['users']
  88. user_table.insert(dict(user))
  89. # 跳轉頁面至登入
  90. return templates.TemplateResponse(name='login.html', context={'request': request})
  91. @app.get('/home', response_class=HTMLResponse)
  92. async def login(request: Request):
  93. return templates.TemplateResponse(name='home.html', context={'request': request})
  94. @app.get('/tower', response_class=HTMLResponse)
  95. async def login(request: Request):
  96. return templates.TemplateResponse(name='tower.html', context={'request': request})
  97. @app.get('/optim', response_class=HTMLResponse)
  98. async def login(request: Request):
  99. return templates.TemplateResponse(name='optim.html', context={'request': request})
  100. @app.get('/vibration', response_class=HTMLResponse)
  101. async def login(request: Request):
  102. return templates.TemplateResponse(name='vibration.html', context={'request': request})
  103. @app.get('/history', response_class=HTMLResponse)
  104. async def login(request: Request):
  105. return templates.TemplateResponse(name='history.html', context={'request': request})
  106. @app.get('/device', response_class=HTMLResponse)
  107. async def login(request: Request):
  108. return templates.TemplateResponse(name='device.html', context={'request': request})
  109. @app.get('/system', response_class=HTMLResponse)
  110. async def login(request: Request):
  111. return templates.TemplateResponse(name='system.html', context={'request': request})
  112. # Login funtion part
  113. def check_user_exists(username):
  114. db = dataset.connect('mysql://choozmo:pAssw0rd@db.ptt.cx:3306/aaron_testdb?charset=utf8mb4')
  115. if int(next(iter(db.query('SELECT COUNT(*) FROM aaron_testdb.users WHERE userName = "'+username+'"')))['COUNT(*)']) > 0:
  116. return True
  117. else:
  118. return False
  119. def get_user(username: str):
  120. """ 取得使用者資訊(Model) """
  121. db = dataset.connect('mysql://choozmo:pAssw0rd@db.ptt.cx:3306/aaron_testdb?charset=utf8mb4')
  122. if not check_user_exists(username): # if user don't exist
  123. return False
  124. user_dict = next(
  125. iter(db.query('SELECT * FROM aaron_testdb.users where userName ="'+username+'"')))
  126. user = models.User(**user_dict)
  127. return user
  128. def user_register(user):
  129. db = dataset.connect('mysql://choozmo:pAssw0rd@db.ptt.cx:3306/aaron_testdb?charset=utf8mb4')
  130. table = db['users']
  131. user.password = get_password_hash(user.password)
  132. table.insert(dict(user))
  133. def get_password_hash(password):
  134. """ 加密密碼 """
  135. return pwd_context.hash(password)
  136. def verify_password(plain_password, hashed_password):
  137. """ 驗證密碼(hashed) """
  138. return pwd_context.verify(plain_password, hashed_password)
  139. def authenticate_user(username: str, password: str):
  140. """ 連線DB,讀取使用者是否存在。 """
  141. db = dataset.connect('mysql://choozmo:pAssw0rd@db.ptt.cx:3306/aaron_testdb?charset=utf8mb4')
  142. if not check_user_exists(username): # if user don't exist
  143. return False
  144. user_dict = next(iter(db.query('SELECT * FROM aaron_testdb.users where userName ="'+username+'"')))
  145. user = models.User(**user_dict)
  146. if not verify_password(password, user.password):
  147. return False
  148. return user
  149. def create_access_token(data: dict, expires_delta: Optional[timedelta] = None):
  150. """ 創建token,並設定過期時間。 """
  151. to_encode = data.copy()
  152. if expires_delta:
  153. expire = datetime.utcnow() + expires_delta
  154. else:
  155. expire = datetime.utcnow() + timedelta(minutes=15)
  156. to_encode.update({"exp": expire})
  157. encoded_jwt = jwt.encode(to_encode, SECRET_KEY, algorithm=ALGORITHM)
  158. return encoded_jwt