mirror of
https://github.com/aljazceru/CTFd.git
synced 2026-02-05 22:34:29 +01:00
2.5.0 / 2020-06-02 ================== **General** * Use a session invalidation strategy inspired by Django. Newly generated user sessions will now include a HMAC of the user's password. When the user's password is changed by someone other than the user the previous HMACs will no longer be valid and the user will be logged out when they next attempt to perform an action. * A user and team's place, and score are now cached and invalidated on score changes. **API** * Add `/api/v1/challenges?view=admin` to allow admin users to see all challenges regardless of their visibility state * Add `/api/v1/users?view=admin` to allow admin users to see all users regardless of their hidden/banned state * Add `/api/v1/teams?view=admin` to allow admin users to see all teams regardless of their hidden/banned state * The scoreboard endpoints `/api/v1/scoreboard` & `/api/v1/scoreboard/top/[count]` should now be more performant because score and place for Users/Teams are now cached **Deployment** * `docker-compose` now provides a basic nginx configuration and deploys nginx on port 80 **Miscellaneous** * The `get_config` and `get_page` config utilities now use SQLAlchemy Core instead of SQLAlchemy ORM for slight speedups * Update Flask-Migrate to 2.5.3 and regenerate the migration environment. Fixes using `%` signs in database passwords.
82 lines
2.3 KiB
Python
82 lines
2.3 KiB
Python
from flask import request
|
|
from flask_caching import Cache
|
|
|
|
cache = Cache()
|
|
|
|
|
|
def make_cache_key(path=None, key_prefix="view/%s"):
|
|
"""
|
|
This function mostly emulates Flask-Caching's `make_cache_key` function so we can delete cached api responses.
|
|
Over time this function may be replaced with a cleaner custom cache implementation.
|
|
:param path:
|
|
:param key_prefix:
|
|
:return:
|
|
"""
|
|
if path is None:
|
|
path = request.endpoint
|
|
cache_key = key_prefix % path
|
|
return cache_key
|
|
|
|
|
|
def clear_config():
|
|
from CTFd.utils import _get_config, get_app_config
|
|
|
|
cache.delete_memoized(_get_config)
|
|
cache.delete_memoized(get_app_config)
|
|
|
|
|
|
def clear_standings():
|
|
from CTFd.models import Users, Teams
|
|
from CTFd.utils.scores import get_standings, get_team_standings, get_user_standings
|
|
from CTFd.api.v1.scoreboard import ScoreboardDetail, ScoreboardList
|
|
from CTFd.api import api
|
|
|
|
cache.delete_memoized(get_standings)
|
|
cache.delete_memoized(get_team_standings)
|
|
cache.delete_memoized(get_user_standings)
|
|
cache.delete_memoized(Users.get_score)
|
|
cache.delete_memoized(Users.get_place)
|
|
cache.delete_memoized(Teams.get_score)
|
|
cache.delete_memoized(Teams.get_place)
|
|
cache.delete(make_cache_key(path="scoreboard.listing"))
|
|
cache.delete(make_cache_key(path=api.name + "." + ScoreboardList.endpoint))
|
|
cache.delete(make_cache_key(path=api.name + "." + ScoreboardDetail.endpoint))
|
|
cache.delete_memoized(ScoreboardList.get)
|
|
|
|
|
|
def clear_pages():
|
|
from CTFd.utils.config.pages import get_page, get_pages
|
|
|
|
cache.delete_memoized(get_pages)
|
|
cache.delete_memoized(get_page)
|
|
|
|
|
|
def clear_user_recent_ips(user_id):
|
|
from CTFd.utils.user import get_user_recent_ips
|
|
|
|
cache.delete_memoized(get_user_recent_ips, user_id=user_id)
|
|
|
|
|
|
def clear_user_session(user_id):
|
|
from CTFd.utils.user import get_user_attrs
|
|
|
|
cache.delete_memoized(get_user_attrs, user_id=user_id)
|
|
|
|
|
|
def clear_all_user_sessions():
|
|
from CTFd.utils.user import get_user_attrs
|
|
|
|
cache.delete_memoized(get_user_attrs)
|
|
|
|
|
|
def clear_team_session(team_id):
|
|
from CTFd.utils.user import get_team_attrs
|
|
|
|
cache.delete_memoized(get_team_attrs, team_id=team_id)
|
|
|
|
|
|
def clear_all_team_sessions():
|
|
from CTFd.utils.user import get_team_attrs
|
|
|
|
cache.delete_memoized(get_team_attrs)
|