Skip to content

Commit

Permalink
Send/require a cookie header on digest-auth
Browse files Browse the repository at this point in the history
Also fix an import.
  • Loading branch information
sigmavirus24 committed Jul 19, 2013
1 parent bde5c81 commit 4870f70
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 3 deletions.
4 changes: 3 additions & 1 deletion httpbin/core.py
Original file line number Diff line number Diff line change
Expand Up @@ -356,8 +356,10 @@ def digest_auth(qop=None, user='user', passwd='passwd'):
auth.set_digest('[email protected]', nonce, opaque=opaque,
qop=('auth', 'auth-int') if qop is None else (qop, ))
response.headers['WWW-Authenticate'] = auth.to_header()
response.headers['Set-Cookie'] = 'fake=fake_value'
return response
elif not check_digest_auth(user, passwd):
elif not (check_digest_auth(user, passwd) and
request.headers.get('Cookie')):
return status_code(401)
return jsonify(authenticated=True, user=user)

Expand Down
4 changes: 2 additions & 2 deletions manage.py
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
# -*- coding: utf-8 -*-

from httpbin import app
from flaskext.script import Manager, Command
from flask.ext.script import Manager, Command


manager = Manager(app)
Expand All @@ -15,4 +15,4 @@ def hello():


if __name__ == "__main__":
manager.run()
manager.run()

0 comments on commit 4870f70

Please sign in to comment.