aio-libs / aio-libs/aiohttp

Warn the user when Authorization header is dropped from the request

Abierto
#9,694 10 comentarios 0 reacciones 0 asignados Ver en GitHub
enhancement reproducer: missing
Lenguaje dominante
Python
Estrellas
16.5k
Forks
2.4k
Merge medio
17 h 22 min
PR fusionados (30 d)
212

Descripción

### Is your feature request related to a problem?

As per the documentation -
```
Authorization header will be removed if you get redirected to a different host or protocol.
```
However this happens silently and can lead to confusion for the programmer.

### Describe the solution you'd like

The library should throw a warning letting the user know that the header has been dropped.
I went through the code and it seems the change below should be sufficient -
```diff
diff --git a/aiohttp/client.py b/aiohttp/client.py
index dc1ab674..8154b11f 100644
--- a/aiohttp/client.py
+++ b/aiohttp/client.py
@@ -756,7 +756,13 @@ class ClientSession:
and url.origin() != redirect_origin
):
auth = None
- headers.pop(hdrs.AUTHORIZATION, None)
+ auth_header = headers.pop(hdrs.AUTHORIZATION, None)
+ if auth_header:
+ warnings.warn(
+ message = "Authorization header has been removed from the request",
+ category = RuntimeWarning,
+ source = self,
+ )

url = parsed_redirect_url
```

### Describe alternatives you've considered

-

### Related component

Client

### Additional context

_No response_

### Code of Conduct

- [X] I agree to follow the aio-libs Code of Conduct

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.