Add secure password storing (#4)

* Added xdg-compliant path for Linux and macOS

Created config.py

Moved system path logic to config.py

* Added secure password storing with keyring

* fixed not showing login screen if no password is saved

* Update readme with new config info

* add pywin32 lib
This commit is contained in:
Szymon
2026-02-15 13:21:23 +01:00
committed by GitHub
parent 876463d7c5
commit e48ed5370a
3 changed files with 26 additions and 13 deletions

View File

@@ -30,17 +30,12 @@ zutui
`ctrl`+`q` - Quit `ctrl`+`q` - Quit
# Sidenotes # Sidenotes
- config is stored @ `~/zutui/config.json` ## Config
- On Unix like is stored @ `~/.config/zutui/config.json`
- On Windows is stored @ `~/zutui/config.json`
- so are `grades_cache.json` - so are `grades_cache.json`
- in plaintext.....
##### As of right now I don't see any MUCH better way. ##### Feel free to pull request if you're smarter :)
##### I mean we could simply encrypt and decrypt it during runtime, but... does it really make it any more secure?
##### And we can't really store it in any form of a _hash_ as we have to log in everytime with plain text anyways...
##### However feel free to pull request if you're smarter :)
# TODO: # TODO:
- [x] **Nothing** - [x] **Nothing**

View File

@@ -8,10 +8,12 @@ setup(
"requests", "requests",
"beautifulsoup4", "beautifulsoup4",
"textual", "textual",
"keyring",
"pywin32"
], ],
entry_points={ entry_points={
'console_scripts': [ 'console_scripts': [
'zutui=zut_app.zutui:main', 'zutui=zut_app.zutui:main',
], ],
}, },
) )

View File

@@ -1,5 +1,7 @@
import json import json
import os import os
import keyring
from keyring.errors import KeyringError
from datetime import datetime from datetime import datetime
from textual.app import App, ComposeResult from textual.app import App, ComposeResult
from textual.containers import Container from textual.containers import Container
@@ -54,9 +56,20 @@ class LoginScreen(Screen):
if success: if success:
try: try:
with open(CONFIG_FILE, "w") as f: with open(CONFIG_FILE, "w") as f:
json.dump({"username": user, "password": password}, f) json.dump({"username": user}, f)
keyring.set_password("zutui", user, password)
except KeyringError as e:
error = e
self.app.call_from_thread(
lambda:
self.app.notify(
f"Błąd: {str(error)}",
title="Błąd zapisu hasła do systemowego menedżera haseł",
severity="warning",
timeout=5
)
)
except: pass except: pass
def do_switch(): def do_switch():
self.app.switch_screen(DashboardScreen()) self.app.switch_screen(DashboardScreen())
self.app.call_from_thread(do_switch) self.app.call_from_thread(do_switch)
@@ -406,7 +419,10 @@ class ZutApp(App):
try: try:
with open(CONFIG_FILE, "r") as f: with open(CONFIG_FILE, "r") as f:
creds = json.load(f) creds = json.load(f)
self.zut_client = ZUT(creds["username"], creds["password"]) password = keyring.get_password("zutui", creds["username"])
if password is None:
raise ValueError("Hasło nie zostało znalezione")
self.zut_client = ZUT(creds["username"], password)
self.push_screen(DashboardScreen()) self.push_screen(DashboardScreen())
except: except:
self.push_screen(LoginScreen()) self.push_screen(LoginScreen())