INNER CODE UNIT · Python

api_auth

The-Art-of-Hacking/websploit · additional-labs/token-tower/app.py:810

def api_auth():
    """API authentication endpoint"""
    data = request.get_json() or {}
    username = data.get('username', '')
    password = data.get('password', '')
    algorithm = data.get('algorithm', 'HS256')
    
    if username not in USERS or USERS[username]['password'] != password:
        return jsonify({"error": "Invalid credentials"}), 401
    
    user = USERS[username]
    payload = {
        "user": username,
        "user_id": user['id'],
        "role": user['role'],
        "iat": datetime.datetime.utcnow(),
        "exp": datetime.datetime.utcnow() + datetime.timedelta(hours=1)
    }

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…