INNER CODE UNIT · Python

guard

yashab-cyber/HackGpt · workbench/server.py:348

    def guard(self, api):
        port = self.server.server_port
        hosts = {"127.0.0.1:" + str(port), "localhost:" + str(port)}
        if self.headers.get("Host") not in hosts:
            self.reply(403, {"error": "Invalid Host; use the loopback launch address"})
            return False
        origin = self.headers.get("Origin")
        if origin is not None and origin not in {"http://" + h for h in hosts}:
            self.reply(403, {"error": "Cross-origin requests are not allowed"})
            return False
        if api:
            supplied = self.headers.get("Authorization", "")
            expected = "Bearer " + self.server.token
            if not hmac.compare_digest(supplied.encode(), expected.encode()):
                self.reply(
                    401, {"error": "Unlock this session with the local launch token"}
                )
                return False

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…