How does default_token_generator store tokens?

前端 未结 1 1063
时光说笑
时光说笑 2021-02-20 02:39

I recently built a Django-based authentication system using a tutorial. Within this System I created a token within a forms.py. This Token is then send (as a link) in an activat

1条回答
  •  暗喜
    暗喜 (楼主)
    2021-02-20 03:01

    A token consist of a timestamp and a HMAC value. HMAC is a keyed hashing function: hashing uses a secret key (by default settings.SECRET_KEY) to get a unique value, but "unhashing" is impossible with or without the key.

    The hash combines four values:

    • The user's primary key.
    • The user's hashed password.
    • The user's last login timestamp.
    • The current timestamp.

    The token then consists of the current timestamp and the hash of these four values. The first three values are already in the database, and the fourth value is part of the token, so Django can verify the token at any time.

    By including the user's hashed password and last login timestamp in the hash, a token is automatically invalidated when the user logs in or changes their password. The current timestamp is also checked to see if the token has expired. Note that even though the current timestamp is included in the token (as a base36 encoded string), if an attacker changes the value, the hash changes as well and the token is rejected.

    0 讨论(0)
提交回复
热议问题