secret as header, not cookie

This commit is contained in:
norohind 2021-12-08 18:02:17 +03:00
parent 2b134d26f4
commit 71fa51f69a
Signed by: norohind
GPG Key ID: 01C3BECC26FB59E1

4
web.py
View File

@ -11,9 +11,9 @@ logger.propagate = False
def check_secret(req: falcon.request.Request, resp: falcon.response.Response, resource, params) -> None:
cookies_secret = req.get_cookie_values('key')
cookies_secret = req.headers.get('AUTH')
if cookies_secret is None or cookies_secret[0] != config.access_key:
if cookies_secret != config.access_key:
raise falcon.HTTPForbidden