Zope 5.8.3受限Python中cryptography verify方法授权失败问题
Zope 5.8.3中Ed25519PublicKey.verify()方法的权限配置问题
在Zope从5.5.1升级到5.8.3后,ZMI内的Python脚本调用cryptography.hazmat.primitives.asymmetric.ed25519.Ed25519PublicKey.verify()时触发Unauthorized: Cannot access verify in this context错误。已配置模块、类的访问权限,from_public_bytes()方法可正常使用,但verify()方法始终被权限拦截,目前只能通过外部方法绕过,希望恢复ZMI内直接调用的能力。
问题原因
Zope的受限Python环境中,仅允许模块和类的访问不足以让类方法被调用——需要显式声明类的特定方法为公开可访问。5.8.3版本的权限控制逻辑相比5.5.1更严格,默认不再自动开放类的所有方法。
解决方案
在权限配置代码中,为Ed25519PublicKey类添加verify()方法的公开权限声明。修改__init__.py中的相关配置:
from Products.PythonScripts.Utility import allow_module, allow_class from AccessControl import ModuleSecurityInfo, ClassSecurityInfo # 原有模块允许配置保持不变 allow_module("base64") allow_module("Crypto") allow_module("Crypto.Cipher") allow_module("cryptography") allow_module("cryptography.exceptions") allow_module("cryptography.fernet") allow_module("cryptography.hazmat") allow_module("cryptography.hazmat.primitives") allow_module("cryptography.hazmat.primitives.asymmetric") allow_module("cryptography.hazmat.primitives.asymmetric.ed25519") allow_module("cryptography.hazmat.primitives.asymmetric.x25519") allow_module("cryptography.hazmat.primitives.kdf.hkdf") allow_module("json") allow_module("ZcPassword") # 原有类允许配置保持不变 from Crypto.Cipher import ChaCha20_Poly1305 allow_class(ChaCha20_Poly1305) from Crypto.Cipher.ChaCha20_Poly1305 import ChaCha20Poly1305Cipher allow_class(ChaCha20Poly1305Cipher) from cryptography.exceptions import InvalidSignature allow_class(InvalidSignature) from cryptography.fernet import Fernet allow_class(Fernet) from cryptography.hazmat.primitives import hashes allow_class(hashes) from cryptography.hazmat.primitives.asymmetric import ec allow_class(ec) from cryptography.hazmat.primitives.asymmetric import ed25519 allow_class(ed25519) from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey allow_class(Ed25519PublicKey) # 新增:为Ed25519PublicKey类声明verify方法为公开可访问 Ed25519PublicKey.security = ClassSecurityInfo() Ed25519PublicKey.security.declarePublic('verify') from cryptography.hazmat.primitives.asymmetric.x25519 import X25519PrivateKey allow_class(X25519PrivateKey) from cryptography.hazmat.primitives.asymmetric.x25519 import X25519PublicKey allow_class(X25519PublicKey) from cryptography.hazmat.primitives.kdf.hkdf import HKDF allow_class(HKDF)
验证说明
修改配置后重启Zope,原测试脚本即可在ZMI内正常运行,无需依赖外部方法。脚本本身逻辑无问题,仅需通过上述配置开放verify()方法的访问权限。
内容的提问来源于stack exchange,提问作者kittonian
相关产品推荐
相关产品推荐

