-
Notifications
You must be signed in to change notification settings - Fork 0
/
users.py
75 lines (56 loc) · 1.54 KB
/
users.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
import secrets
from db import db
from flask import session
from werkzeug.security import check_password_hash
import basket
def register_user(username, password_hash_value):
sql = """INSERT INTO
users (
username,
password
)
VALUES (
:username,
:password)
"""
db.session.execute(sql, {"username":username, "password":password_hash_value})
db.session.commit()
def login(username, password):
sql = """SELECT
id,
password
FROM
users
WHERE
username=:username
"""
result = db.session.execute(sql, {"username":username})
user = result.fetchone()
if not user:
return False
hash_value = user.password
if check_password_hash(hash_value, password):
session["user_id"] = user.id
session["username"] = username
session["csrf_token"] = secrets.token_hex(16)
return True
return False
def get_user_id():
return session.get("user_id", 0)
def logout():
basket.empty_basket(session["user_id"])
del session["user_id"]
del session["username"]
del session["csrf_token"]
def username_in_use(username):
sql = """SELECT
id
FROM
users
WHERE
username=:username
"""
result = db.session.execute(sql, {"username":username}).fetchone()
if result:
return True
return False