INNER CODE UNIT · Python
api_auth
The-Art-of-Hacking/websploit · additional-labs/token-tower/app.py:810
def api_auth():
"""API authentication endpoint"""
data = request.get_json() or {}
username = data.get('username', '')
password = data.get('password', '')
algorithm = data.get('algorithm', 'HS256')
if username not in USERS or USERS[username]['password'] != password:
return jsonify({"error": "Invalid credentials"}), 401
user = USERS[username]
payload = {
"user": username,
"user_id": user['id'],
"role": user['role'],
"iat": datetime.datetime.utcnow(),
"exp": datetime.datetime.utcnow() + datetime.timedelta(hours=1)
}