mirror of
https://github.com/norohind/FDEV-CAPI-Handler.git
synced 2025-06-07 10:53:23 +03:00
secret as header, not cookie
This commit is contained in:
parent
2b134d26f4
commit
71fa51f69a
4
web.py
4
web.py
@ -11,9 +11,9 @@ logger.propagate = False
|
||||
|
||||
|
||||
def check_secret(req: falcon.request.Request, resp: falcon.response.Response, resource, params) -> None:
|
||||
cookies_secret = req.get_cookie_values('key')
|
||||
cookies_secret = req.headers.get('AUTH')
|
||||
|
||||
if cookies_secret is None or cookies_secret[0] != config.access_key:
|
||||
if cookies_secret != config.access_key:
|
||||
raise falcon.HTTPForbidden
|
||||
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user