bird-house / bird-house/twitcher

Unauthorized response browser auto-popup window for login

Open
#96 0 comments 0 reactions 0 assignees View on GitHub
pavics security
Dominant language
Python
Stars
15
Forks
5
Avg merge
4d 14h
Merged PRs (30d)
4

Description

`WWW-Authenticate` header should _always_ be returned in the response when 401 occurs from a missing AuthN/AuthZ headers. https://tools.ietf.org/html/rfc2617#section-3.2.1

This would allow web browsers to popup a login window to enter credentials and login.

To redirect the login request at the right place, we could either use `WWW-Authenticate: digest` with `domain=` (see above reference), or using the following parameter (experimental since 2017?),
`Location-When-Unauthenticated` Parameter
https://tools.ietf.org/html/rfc8053#section-4.3

For a user accessing a web service via his browser using the proxy URL, this would greatly help him login without having to figure out how/where to login on the requested instance (https://github.com/Ouranosinc/Magpie, some remote Keycloak service, local Twitcher token, etc.).

Side note, for a web browser request that would require to bypass this auto login window/popup feature, the `X-Requested-With: XMLHttpRequest` request header seems like a wide spread method.
https://stackoverflow.com/questions/9859627

Side-side note (@fmigneault)
Noting this feature here before it fall between cracks.
relates to Ouranosinc/Magpie#330

Contributor guide

No contributing guide indexed for this repository

Research direction

No source file, test, or entry point is named. Start by tracing the 401 response path and review RFC 2617, RFC 8053, and the related Magpie#330 issue; done means the authentication-header behavior and any browser-popup bypass are decided and tested.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api, authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.