From cfdedc1110da3b42de7803b286458e3a6ed0ade8 Mon Sep 17 00:00:00 2001 From: MrEisbear Date: Fri, 25 Jul 2025 23:27:20 -0500 Subject: [PATCH] Implement BID generation This commit implements automatic BID generation during registration --- interbend/auth.py | 8 +++++++ interbend/routes/auth_routes.py | 38 ++++++++++++++++++++++++++++----- 2 files changed, 41 insertions(+), 5 deletions(-) diff --git a/interbend/auth.py b/interbend/auth.py index 2bc1b98..dcf65ae 100644 --- a/interbend/auth.py +++ b/interbend/auth.py @@ -1,3 +1,5 @@ +import secrets +import string from functools import wraps from flask import request, jsonify, current_app import jwt @@ -8,6 +10,12 @@ def _getconfig(): jwt_expire = current_app.config['JWT_EXPIRE'] # In days return jwt_key, jwt_expire +def r_gen2(length): + if length < 1: + raise ValueError("Length must be at least 1") + first_digit = secrets.choice(string.digits.replace('0', '')) + return first_digit + ''.join(secrets.choice(string.digits) for _ in range(length - 1)) + def jwt_required(f): @wraps(f) def decorated_function(*args, **kwargs): diff --git a/interbend/routes/auth_routes.py b/interbend/routes/auth_routes.py index c92f642..f350714 100644 --- a/interbend/routes/auth_routes.py +++ b/interbend/routes/auth_routes.py @@ -10,14 +10,40 @@ auth_bp = Blueprint('auth_bp', __name__) @auth_bp.route('/register', methods=['POST']) def register(): data = request.get_json() - bid = data.get('bid') + # bid = data.get('bid') + # Bid is now generated by API username = data.get('username') email = data.get('email') password = data.get('password') - if not username or not email or not password or not bid: - return jsonify({"error": "Username, email, and password are required."}), 400 + if not username or not email or not password: + return jsonify({"error": "Username, email, and password are required."}), 404 password_hash = generate_password_hash(password) + try: + with db.cursor(dictionary=True) as cur: + cur.execute("SELECT * FROM users WHERE email = %s", (email,)) + if cur.fetchone(): + return jsonify({"error": "Email already exists."}), 409 + except mysql.connector.Error as err: + db.rollback() + current_app.logger.error(f"Database error in register: {err}") + return jsonify({"error": "Database Error"}), 500 + for i in range(6): + if i == 5: + return jsonify({"error": "Could not generate valid BID"}), 500 + bid = "M-".join(r_gen2(16)) + try: + with db.cursor(dictionary=True) as cur: + cur.execute("SELECT * FROM users WHERE bid = %s", (bid,)) + if cur.fetchone: + continue + else: + break + except mysql.connector.Error as err: + db.rollback() + current_app.logger.error(f"Database error in register: {err}") + return jsonify({"error": "Database Error"}), 500 + try: with db.cursor(dictionary=True) as cur: cur.execute("INSERT INTO users (bid, username, email, password_hash) VALUES (%s, %s, %s, %s)", @@ -27,8 +53,10 @@ def register(): response = make_response(jsonify({"message": "Login successful."}), 201) response.set_cookie('token', token, httponly=True, samesite='Strict', max_age=30 * 24 * 60 * 60) return response - except mysql.connector.IntegrityError: - return jsonify({"error": "Username or email already exists."}), 409 + except mysql.connector.Error as err: + db.rollback() + current_app.logger.error(f"Database error in register: {err}") + return jsonify({"error": "Database Error"}), 500