INNER CODE UNIT · Python
authorization_check
OWASP/Python-Honeypot · api/server.py:200
def authorization_check():
"""
check if IP filtering applied and API address is in whitelist also
API Key is valid
Returns:
None or Abort(403) or Abort(401)
"""
# IP Limitation
white_list_enabled = app.config["OWASP_HONEYPOT_CONFIG"]["api_client_white_list"]
white_list_ips = app.config["OWASP_HONEYPOT_CONFIG"]["api_client_white_list_ips"]
api_access_without_key = app.config["OWASP_HONEYPOT_CONFIG"]["api_access_without_key"]
if white_list_enabled:
if flask_request.remote_addr not in white_list_ips:
abort(403, "unauthorized IP")
if not api_access_without_key:
is_authorized()