#!/usr/bin/env python """ One-time interactive Garmin login. Garmin accounts with two-factor auth cannot be logged into by the web service: the library asks for the MFA code on stdin, and a gunicorn worker has none — the attempt fails with "EOFError: EOF when reading a line". This script does that login in a terminal, where a code can actually be typed, and stores the resulting OAuth tokens in the database. Every later sync loads those tokens and skips the login entirely. They stay valid for roughly a year; re-run this when a sync starts reporting an expired session. Usage (on the NAS): cd ~/apps/garmin-health-lab/backend .venv/bin/python garmin_login.py Add --email to pick an account when more than one is registered. """ import argparse import getpass import sys import db from services import garmin as garmin_svc def pick_user(email=None): if email: row = db.query_one("SELECT id, email, garmin_email FROM users WHERE email = ?", [email]) if not row: sys.exit(f"找不到账号: {email}") return row rows = db.query_all("SELECT id, email, garmin_email FROM users ORDER BY created_at") if not rows: sys.exit("数据库里还没有账号,请先在网页上注册。") if len(rows) == 1: return rows[0] print("有多个账号,请选择:") for i, r in enumerate(rows, 1): print(f" {i}) {r['email']} (Garmin: {r['garmin_email']})") choice = input("序号: ").strip() try: return rows[int(choice) - 1] except (ValueError, IndexError): sys.exit("选择无效") def main(): parser = argparse.ArgumentParser(description="一次性 Garmin 登录,保存令牌") parser.add_argument("--email", help="要绑定的本站账号邮箱") parser.add_argument("--garmin-email", help="Garmin 账号邮箱(默认用注册时填的)") args = parser.parse_args() db.init_db() user = pick_user(args.email) garmin_email = args.garmin_email or user["garmin_email"] print(f"本站账号 : {user['email']}") print(f"Garmin : {garmin_email}") print() if garmin_svc.has_token(user["id"]): if input("已存在登录令牌,要覆盖吗?[y/N] ").strip().lower() != "y": return password = getpass.getpass("Garmin 密码: ") if not password: sys.exit("密码不能为空") Garmin = garmin_svc._import_garmin() client = Garmin(email=garmin_email, password=password, is_cn=garmin_svc._is_cn()) def ask_mfa(): # garth's built-in prompt is a bare English input() that is easy to # miss in the surrounding output, so this replaces it with something # unmistakable. print("\n" + "=" * 52) print(" 账号开启了两步验证,请查收短信/邮件中的验证码") print("=" * 52) while True: code = input(" 验证码(6 位数字): ").strip() if code: return code print(" 验证码不能为空,请重新输入。") print("\n正在登录……") try: # Call garth directly rather than Garmin.login(): only this path lets # the MFA prompt be replaced. The two lines afterwards are what # Garmin.login() would otherwise populate. client.garth.login(garmin_email, password, prompt_mfa=ask_mfa) client.display_name = client.garth.profile["displayName"] client.full_name = client.garth.profile["fullName"] except Exception as e: sys.exit(f"\n登录失败: {type(e).__name__}: {e}") garmin_svc.save_token(user["id"], client.garth.dumps(), garmin_email) print(f"\n登录成功:{client.display_name}") print("令牌已保存到数据库,之后网页上的同步不再需要密码或验证码。") print("令牌大约一年后过期,届时重跑本脚本即可。") if __name__ == "__main__": main()