mirror of
https://github.com/dashpay/dash.git
synced 2024-12-25 03:52:49 +01:00
9369fde159
6be7d14d243eeeaaf6b4b98c3359c3e1695f2046 Properly generate salt in rpcauth.py, update tests (Carl Dong) Pull request description: Previously, when iterating over bytes of the generated salt to construct a hex string, only one character would be outputted when the byte is less than 0x10. Meaning that for a 16 byte salt, the hex string might be less than 32 characters and collisions would occur. Tree-SHA512: 7038ecbbac846cd1851112396acd8a04475685f5b6f786e4e7316acba4a56cc711c275b7f52f0f2b6bc6cfdc0c0d9d39c3afeb2c0aff3a30fde516bf642fdf9f
45 lines
1.3 KiB
Python
Executable File
45 lines
1.3 KiB
Python
Executable File
#!/usr/bin/env python3
|
|
# Copyright (c) 2015-2017 The Bitcoin Core developers
|
|
# Distributed under the MIT software license, see the accompanying
|
|
# file COPYING or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
import sys
|
|
import os
|
|
import base64
|
|
from binascii import hexlify
|
|
import hmac
|
|
|
|
def generate_salt(size):
|
|
"""Create size byte hex salt"""
|
|
return hexlify(os.urandom(size)).decode()
|
|
|
|
def generate_password():
|
|
"""Create 32 byte b64 password"""
|
|
return base64.urlsafe_b64encode(os.urandom(32)).decode('utf-8')
|
|
|
|
def password_to_hmac(salt, password):
|
|
m = hmac.new(bytearray(salt, 'utf-8'), bytearray(password, 'utf-8'), 'SHA256')
|
|
return m.hexdigest()
|
|
|
|
def main():
|
|
if len(sys.argv) < 2:
|
|
sys.stderr.write('Please include username (and an optional password, will generate one if not provided) as an argument.\n')
|
|
sys.exit(0)
|
|
|
|
username = sys.argv[1]
|
|
|
|
# Create 16 byte hex salt
|
|
salt = generate_salt(16)
|
|
if len(sys.argv) > 2:
|
|
password = sys.argv[2]
|
|
else:
|
|
password = generate_password()
|
|
password_hmac = password_to_hmac(salt, password)
|
|
|
|
print('String to be appended to bitcoin.conf:')
|
|
print('rpcauth={0}:{1}${2}'.format(username, salt, password_hmac))
|
|
print('Your password:\n{0}'.format(password))
|
|
|
|
if __name__ == '__main__':
|
|
main()
|