aio-libs / aio-libs/aiohttp

Warn the user when Authorization header is dropped from the request

Offen
#9,694 10 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement reproducer: missing
Vorherrschende Sprache
Python
Sterne
16.5k
Forks
2.4k
Ø Merge
17 Std. 22 Min.
Gemergte PRs (30 T.)
212

Beschreibung

### Is your feature request related to a problem?

As per the documentation -
```
Authorization header will be removed if you get redirected to a different host or protocol.
```
However this happens silently and can lead to confusion for the programmer.

### Describe the solution you'd like

The library should throw a warning letting the user know that the header has been dropped.
I went through the code and it seems the change below should be sufficient -
```diff
diff --git a/aiohttp/client.py b/aiohttp/client.py
index dc1ab674..8154b11f 100644
--- a/aiohttp/client.py
+++ b/aiohttp/client.py
@@ -756,7 +756,13 @@ class ClientSession:
and url.origin() != redirect_origin
):
auth = None
- headers.pop(hdrs.AUTHORIZATION, None)
+ auth_header = headers.pop(hdrs.AUTHORIZATION, None)
+ if auth_header:
+ warnings.warn(
+ message = "Authorization header has been removed from the request",
+ category = RuntimeWarning,
+ source = self,
+ )

url = parsed_redirect_url
```

### Describe alternatives you've considered

-

### Related component

Client

### Additional context

_No response_

### Code of Conduct

- [X] I agree to follow the aio-libs Code of Conduct

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.