Files
felhom.eu/documentation/audits/gate-rollout-2026-09-29/B/ro_su3.py
T

37 lines
2.9 KiB
Python

# A stranger (no cookies) tries each app's own sign-up after the gate opened.
import sys, secrets, urllib.parse
sys.path.insert(0, '.')
import ro
from ro import w, host
from browser import Browser
def call(app, n):
s = Browser("stranger"); pw = "Xx" + secrets.token_hex(8) + "9"; em = n + "@x.hu"; o = {"Origin": f"https://{host(app)}"}
if app == "homebox": return s.req(f"https://{host(app)}/api/v1/users/register", "POST", body={"name": n, "email": em, "password": pw}, accept="application/json")
if app == "papra": return s.req(f"https://{host(app)}/api/auth/sign-up/email", "POST", body={"email": em, "password": pw, "name": n}, accept="application/json", headers=o)
if app == "sparkyfitness": return s.req(f"https://{host(app)}/api/auth/sign-up/email", "POST", body={"email": em, "password": pw, "name": n}, accept="application/json", headers=o)
if app == "vikunja": return s.req(f"https://{host(app)}/api/v1/register", "POST", body={"username": n, "email": em, "password": pw}, accept="application/json")
if app == "adventurelog":
b = urllib.parse.urlencode({"username": n, "email": em, "password1": pw, "password2": pw, "first_name": "S", "last_name": "S"})
return s.req(f"https://{host(app)}/signup", "POST", body=b, accept="application/json", headers=dict(o, **{"Content-Type": "application/x-www-form-urlencoded", "x-sveltekit-action": "true"}))
def call2(app, n):
s = Browser("stranger"); pw = "Xx" + secrets.token_hex(8) + "9"; em = n + "@x.hu"; o = {"Origin": f"https://{host(app)}"}
if app == "termix": return s.req(f"https://{host(app)}/users/create", "POST", body={"username": n, "password": pw}, accept="application/json")
if app == "gramps-web": return s.req(f"https://{host(app)}/api/users/{n}/register/", "POST", body={"email": em, "password": pw, "full_name": "S"}, accept="application/json")
if app == "wishlist":
b = urllib.parse.urlencode({"name": "S", "username": n, "email": em, "password": pw, "confirmPassword": pw})
return s.req(f"https://{host(app)}/signup", "POST", body=b, accept="application/json", headers=dict(o, **{"Content-Type": "application/x-www-form-urlencoded", "x-sveltekit-action": "true"}))
if app == "opengist":
import re
st, html, _ = s.req(f"https://{host(app)}/-/register")
m = re.search(r'name="_csrf" value="([^"]+)"', html)
if not m:
return st, html[:200], None
b = urllib.parse.urlencode({"username": n, "password": pw, "_csrf": m.group(1)})
st, t, h = s.req(f"https://{host(app)}/-/register", "POST", body=b, headers={"Content-Type": "application/x-www-form-urlencoded", "Origin": o["Origin"]})
return st, (t[:60] if st != 200 else ("landed on " + h[-1][2])), h
return call(app, n)
w.login()
for app in sys.argv[2:]:
st, t, _ = call2(app, sys.argv[1] + secrets.token_hex(2))
w.say(app, f"{sys.argv[1].upper()} sign-up -> {st} closed-answer={'sign-up is closed' in t or 'nem lehet regisztr' in t} {t[:60]!r}")