|
| 1 | +from hashlib import blake2b |
| 2 | +from pickle import UnpicklingError, dumps, loads |
| 3 | +from secrets import compare_digest |
| 4 | +from typing import Any, Tuple |
| 5 | + |
| 6 | +from django.conf import settings |
| 7 | +from django.core.cache.backends.memcached import PyLibMCCache |
| 8 | +from django.core.cache.backends.redis import ( |
| 9 | + RedisCache, RedisCacheClient, RedisSerializer |
| 10 | +) |
| 11 | + |
| 12 | + |
| 13 | +def _sign_data(data: bytes) -> bytes: |
| 14 | + return blake2b( |
| 15 | + data, digest_size=16, |
| 16 | + key=settings.SECRET_KEY.encode() |
| 17 | + ).digest() |
| 18 | + |
| 19 | + |
| 20 | +class SignedRedisCache(RedisCache): |
| 21 | + "A cache binding using redis and signed pickles" |
| 22 | + |
| 23 | + def __init__(self, *args): |
| 24 | + super().__init__(*args) |
| 25 | + |
| 26 | + class _SignedRedisSerializer(RedisSerializer): |
| 27 | + def dumps(self, obj: Any) -> Any: |
| 28 | + if type(obj) is int: |
| 29 | + return obj |
| 30 | + data = dumps(obj, self.protocol) |
| 31 | + return _sign_data(data) + data |
| 32 | + |
| 33 | + def loads(self, data: Any) -> Any: |
| 34 | + try: |
| 35 | + return int(data) |
| 36 | + except ValueError: |
| 37 | + sig, obj = data[:16], data[16:] |
| 38 | + if compare_digest(sig, _sign_data(obj)): |
| 39 | + return loads(obj) |
| 40 | + raise UnpicklingError('Signatures do not match') |
| 41 | + |
| 42 | + class _SignedRedisCacheClient(RedisCacheClient): |
| 43 | + def __init__(self, *args, **kwargs): |
| 44 | + super().__init__(*args, **kwargs) |
| 45 | + self._serializer = _SignedRedisSerializer() |
| 46 | + |
| 47 | + self._class = _SignedRedisCacheClient |
| 48 | + |
| 49 | + |
| 50 | +class SignedPyLibMCCache(PyLibMCCache): |
| 51 | + "A cache binding using pylibmc and signed pickles" |
| 52 | + |
| 53 | + def __init__(self, *args): |
| 54 | + super().__init__(*args) |
| 55 | + |
| 56 | + def _is_pickle(flag: int) -> bool: |
| 57 | + return flag & 23 == 1 |
| 58 | + |
| 59 | + class _SignedMCClient(self._lib.Client): |
| 60 | + def serialize(self, value: Any) -> Tuple[bytes, int]: |
| 61 | + data, flag = super().serialize(value) |
| 62 | + if _is_pickle(flag): |
| 63 | + return _sign_data(data) + data, flag |
| 64 | + return data, flag |
| 65 | + |
| 66 | + def deserialize(self, data: bytes, flag: int) -> Any: |
| 67 | + if _is_pickle(flag): |
| 68 | + sig, obj = data[:16], data[16:] |
| 69 | + if compare_digest(sig, _sign_data(obj)): |
| 70 | + return loads(obj) |
| 71 | + raise UnpicklingError('Signatures do not match') |
| 72 | + return super().deserialize(data, flag) |
| 73 | + |
| 74 | + self._class = _SignedMCClient |
| 75 | + |
| 76 | + |
| 77 | +__all__ = ['SignedRedisCache', 'SignedPyLibMCCache'] |
0 commit comments