X-Git-Url: http://xvm.mit.edu/gitweb/invirt/packages/invirt-vnc-server.git/blobdiff_plain/39e55d15a71400169ea9dc2b4eb813dbeb8666bb..9b53a3b4c06b33ff8e0055ffdfb7059d3f79ba54:/python/vnc/extauth.py diff --git a/python/vnc/extauth.py b/python/vnc/extauth.py index e6d07fe..b7351a3 100644 --- a/python/vnc/extauth.py +++ b/python/vnc/extauth.py @@ -18,11 +18,15 @@ import hmac import base64 import socket import time -import get_port -TOKEN_KEY = "0M6W0U1IXexThi5idy8mnkqPKEq1LtEnlK/pZSn0cDrN" +def getTokenKey(): + token_key = file('/etc/invirt/secrets/vnc-key').read().strip() + while True: + yield token_key +getTokenKey = getTokenKey().next def getPort(name, auth_data): + import get_port if (auth_data["machine"] == name): port = get_port.findPort(name) if port is None: @@ -62,12 +66,11 @@ class VNCAuth(protocol.Protocol): self.otherConn=None def validateToken(self, token): - global TOKEN_KEY self.auth_error = "Invalid token" try: token = base64.urlsafe_b64decode(token) token = cPickle.loads(token) - m = hmac.new(TOKEN_KEY, digestmod=sha) + m = hmac.new(getTokenKey(), digestmod=sha) m.update(token['data']) if (m.digest() == token['digest']): data = cPickle.loads(token['data'])