Depending on when the identity system is able to handle IP addresses,
we'll either use that or this method... Definitely a good feature to
have.

Thanks!
Kevin

On 10/27/05, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote:
>
> oops.
>
> forgot the two import
> === catwalk.py
> ==================================================================
> --- catwalk.py  (revision 6575)
> +++ catwalk.py  (local)
> @@ -4,6 +4,8 @@
>  import decimal
>  import datetime
>  import re
> +import struct
> +import socket
>
>  date_parser = re.compile(r"""^
>    (?P<year>\d{4,4})
> @@ -88,7 +90,23 @@
>        print 'Fail to import model file'
>
>    def checkAccess(self):
> -    if cherrypy.request.remoteAddr in self.allowedHosts: return
> +    def remoteHost():
> +      try: return
> cherrypy.request.headerMap.get("X-Forwarded-For",cherrypy.request.remoteHost).split(",")[-1].strip()
> +      except: return ""
> +    def match_ip(cidr, ip):
> +      if not '/' in cidr: return cidr == ip
> +      else:
> +        try:
> +          b,m = cidr.split('/')
> +          shift = 32 - int(m)
> +          a1 = struct.unpack('!L', socket.inet_aton(b))[0] >> shift
> +          a2 = struct.unpack('!L', socket.inet_aton(ip))[0] >> shift
> +          return a1 == a2
> +        except: return False
> +
> +    ip = remoteHost()
> +    for x in self.allowedHosts:
> +      if match_ip(x, ip): return
>      raise cherrypy.HTTPRedirect(turbogears.url('noacces'))
>
>    @turbogears.expose()
>
> [EMAIL PROTECTED] wrote:
> > Hi,
> >
> > I have made some minor change to catwalk so it can check against ip in
> > the form of '192.168.1.1/24' and also for client comes in through
> > proxy. Please consider applies it.
> >
> > ==================================================================
> > --- catwalk.py  (revision 6575)
> > +++ catwalk.py  (local)
> > @@ -88,7 +88,23 @@
> >        print 'Fail to import model file'
> >
> >    def checkAccess(self):
> > -    if cherrypy.request.remoteAddr in self.allowedHosts: return
> > +    def remoteHost():
> > +      try: return
> > cherrypy.request.headerMap.get("X-Forwarded-For",cherrypy.request.remoteHost).split(",")[-1].strip()
> > +      except: return ""
> > +    def match_ip(cidr, ip):
> > +      if not '/' in cidr: return cidr == ip
> > +      else:
> > +        try:
> > +          b,m = cidr.split('/')
> > +          shift = 32 - int(m)
> > +          a1 = struct.unpack('!L', socket.inet_aton(b))[0] >> shift
> > +          a2 = struct.unpack('!L', socket.inet_aton(ip))[0] >> shift
> > +          return a1 == a2
> > +        except: return False
> > +
> > +    ip = remoteHost()
> > +    for x in self.allowedHosts:
> > +      if match_ip(x, ip): return
> >      raise cherrypy.HTTPRedirect(turbogears.url('noacces'))
> >
> >    @turbogears.expose()
>
>


--
Kevin Dangoor
Author of the Zesty News RSS newsreader

email: [EMAIL PROTECTED]
company: http://www.BlazingThings.com
blog: http://www.BlueSkyOnMars.com

Reply via email to