INNER CODE UNIT · Python
guard
yashab-cyber/HackGpt · workbench/server.py:348
def guard(self, api):
port = self.server.server_port
hosts = {"127.0.0.1:" + str(port), "localhost:" + str(port)}
if self.headers.get("Host") not in hosts:
self.reply(403, {"error": "Invalid Host; use the loopback launch address"})
return False
origin = self.headers.get("Origin")
if origin is not None and origin not in {"http://" + h for h in hosts}:
self.reply(403, {"error": "Cross-origin requests are not allowed"})
return False
if api:
supplied = self.headers.get("Authorization", "")
expected = "Bearer " + self.server.token
if not hmac.compare_digest(supplied.encode(), expected.encode()):
self.reply(
401, {"error": "Unlock this session with the local launch token"}
)
return False