oops.

forgot the two import
=== catwalk.py
==================================================================
--- catwalk.py  (revision 6575)
+++ catwalk.py  (local)
@@ -4,6 +4,8 @@
 import decimal
 import datetime
 import re
+import struct
+import socket

 date_parser = re.compile(r"""^
   (?P<year>\d{4,4})
@@ -88,7 +90,23 @@
       print 'Fail to import model file'

   def checkAccess(self):
-    if cherrypy.request.remoteAddr in self.allowedHosts: return
+    def remoteHost():
+      try: return
cherrypy.request.headerMap.get("X-Forwarded-For",cherrypy.request.remoteHost).split(",")[-1].strip()
+      except: return ""
+    def match_ip(cidr, ip):
+      if not '/' in cidr: return cidr == ip
+      else:
+        try:
+          b,m = cidr.split('/')
+          shift = 32 - int(m)
+          a1 = struct.unpack('!L', socket.inet_aton(b))[0] >> shift
+          a2 = struct.unpack('!L', socket.inet_aton(ip))[0] >> shift
+          return a1 == a2
+        except: return False
+
+    ip = remoteHost()
+    for x in self.allowedHosts:
+      if match_ip(x, ip): return
     raise cherrypy.HTTPRedirect(turbogears.url('noacces'))

   @turbogears.expose()

[EMAIL PROTECTED] wrote:
> Hi,
>
> I have made some minor change to catwalk so it can check against ip in
> the form of '192.168.1.1/24' and also for client comes in through
> proxy. Please consider applies it.
>
> ==================================================================
> --- catwalk.py  (revision 6575)
> +++ catwalk.py  (local)
> @@ -88,7 +88,23 @@
>        print 'Fail to import model file'
>
>    def checkAccess(self):
> -    if cherrypy.request.remoteAddr in self.allowedHosts: return
> +    def remoteHost():
> +      try: return
> cherrypy.request.headerMap.get("X-Forwarded-For",cherrypy.request.remoteHost).split(",")[-1].strip()
> +      except: return ""
> +    def match_ip(cidr, ip):
> +      if not '/' in cidr: return cidr == ip
> +      else:
> +        try:
> +          b,m = cidr.split('/')
> +          shift = 32 - int(m)
> +          a1 = struct.unpack('!L', socket.inet_aton(b))[0] >> shift
> +          a2 = struct.unpack('!L', socket.inet_aton(ip))[0] >> shift
> +          return a1 == a2
> +        except: return False
> +
> +    ip = remoteHost()
> +    for x in self.allowedHosts:
> +      if match_ip(x, ip): return
>      raise cherrypy.HTTPRedirect(turbogears.url('noacces'))
>  
>    @turbogears.expose()

Reply via email to