summaryrefslogtreecommitdiff
path: root/requests/auth.py
Commit message (Collapse)AuthorAgeFilesLines
* Updated references to previous requests/requests GitHub pathNihaal2019-08-191-1/+1
|
* Print the type of the password instead of the password itselfpetar-iv2019-05-201-1/+1
|
* remove final remnants from 2.6Nate Prewitt2018-10-171-2/+2
|
* for RFC-7616 add SHA-256 and SHA-512David Poole2017-11-081-0/+12
|
* fix flake8 indent errorKenneth Reitz2017-05-291-1/+1
|
* new requests namespaceKenneth Reitz2017-05-291-1/+1
|
* Remove some unused imports.Chris Gavin2017-04-251-1/+0
|
* Only send HTTPDigestAuth on 4xx challengesMatthew Medal2017-01-271-0/+6
| | | | Resolves: #3772
* python 2.6 compatibilibyKenneth Reitz2016-12-201-2/+2
|
* Add deprecation warnings for 3.0Ian Cordasco2016-12-091-0/+15
| | | | Add extra test parameter for basic auth encoding
* adding string casting for non-bytes valuesNate Prewitt2016-12-081-2/+16
|
* remove extra importDmitry Klimenko2016-11-171-1/+1
|
* Order of type checkDmitry Klimenko2016-11-171-5/+5
|
* Unable unicode in basic http authDmitry Klimenko2016-11-121-1/+7
| | | Fixed the issue with unicode characters in basic http auth
* Change module of internal references to to_native_str()Brian Bamsch2016-09-271-1/+2
|
* Document bunch of return typesVille Skyttä2016-08-091-1/+8
|
* adding in pep8 fixesNate Prewitt2016-07-201-0/+3
|
* Initialize hash_utf8 to None, preventing NameError. Fixes #3138.Mark Shannon2016-04-291-0/+1
|
* Fix syntax errorMarkus Unterwaditzer2016-01-301-2/+2
|
* cleanup of auth __eq__Kenneth Reitz2016-01-291-12/+8
|
* Add equality functions for authentication handlersNicolas Delvaux2016-01-041-0/+22
|
* requests/auth: Handle an empty 'qop' attribute in a Authenticate challengeMatt Jordan2015-12-051-1/+1
| | | | | | | | | | | | | | | | | Some malfunctioning HTTP servers may return a qop directive with no token, as opposed to correctly omitting the qop directive completely. For example: header: WWW-Authenticate: Digest realm="foobar_api_auth", qop="", nonce="a12059eaaad0b86ece8f62f04cbafed6", algorithm="MD5", stale="false" Prior to this patch, requests would respond with a 'None' Authorization header. While the server is certainly incorrect, this patch updates requests to be more tolerant to this kind of shenaniganry. If we receive an empty string for the value of the qop attribute, we instead treat that as if the qop attribute was simply not provided. Closes #2916
* Merge branch 'auth-digest-multi-thread' of ↵Ian Cordasco2015-07-181-27/+38
|\ | | | | | | https://github.com/exvito/requests into proposed/2.8.0
| * Issue #2334 - HTTPDigestAuth - Renamed thread local attributeexvito2015-04-041-31/+30
| | | | | | | | Per @sigmavirus24 suggestion: private and more readable.
| * Issue #2334 - HTTPDigestAuth - Improved per-thread state initexvito2015-04-031-12/+10
| | | | | | | | Inspired in @tardyp approach.
| * Issue #2334 - HTTPDigestAuth - All state now in thread local storageexvito2015-04-031-27/+38
| | | | | | | | Following feedback from tardyp and @vincentxb.
| * Issue #2334 - HTTPDigestAuth - Replace getattr utilizationexvito2015-04-021-1/+1
| | | | | | | | Following Lukasa + kennethreitz suggestion.
| * Issue #2334 - HTTPAuthDigest - Making it thread-safeexvito2015-04-021-5/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | The existing code counts the number of 401 responses in the num_401_calls authenticator attribute. This is in place so as to ensure the necessary auth header is sent, while avoiding infinite 401 loops (issue #547). This commit makes num_401_calls an instance of threading.local() (previously an integer), using num_401_calls.value as the counter. It ensures that concurrent authentication requests get each their own counter and behave as expected (otherwise every other concurrent request would have its authentication fail).
* | Auth handler calls close instead of raw.close_connSaimadhav Heblikar2015-05-141-1/+1
| |
* | Merge pull request #2427 from luozhaoyu/masterIan Cordasco2015-04-061-1/+2
|\ \ | |/ |/| Bug fix: field uri in digest authentication should not be empty when enc...
| * Bug fix: field uri in digest authentication should not be empty when ↵Zhaoyu Luo2015-01-251-1/+2
| | | | | | | | encounter http redirections
* | Move noncebit to the only place it is usedIan Cordasco2015-01-191-1/+3
|/ | | | | | Since we only allow for "auth" qop-value, hardcode it Fixes #2408
* Fix bug in renegotiating a nonce with the serverIan Cordasco2014-12-231-3/+4
| | | | | | | | | | | If a session runs long enough (without constant activity) then the server can expire the nonce the session has negotiated. If that happens the session will get a new 401 response which we were immediately returning to the user. A user would then have to essentially reinitialize session.auth each time they get an unexpected 401. Also, there's no need for setattr calls when we can simply assign the attribute on the instance.
* Fix HTTPDigestAuth not to treat non-file as a fileAkira Kitada2014-11-131-1/+5
| | | | | Ensure pos is set to None when the body is not a file so that HTTPDigestAuth detects the type of the body correctly.
* Clean up handle_redirect.Yossi Gottlieb2014-10-231-3/+1
|
* Clean up, support all redirects, fix potential endless 401 loop.Yossi Gottlieb2014-10-081-8/+8
|
* A fix for #1979 repeat HTTP digest authentication after redirect.Yossi Gottlieb2014-09-271-0/+9
|
* Avoid unnecessary encode/decode cycles.Cory Benfield2014-06-081-4/+4
|
* Force basic auth strings to native string typeCory Benfield2014-06-081-2/+6
|
* Remove unused loggers.Martijn Pieters2014-02-031-3/+0
|
* Address feedback from #1729Ian Cordasco2013-12-041-2/+2
| | | | - Make the PreparedRequest's cookie jar an implementation detail
* Store the request cookiejar in PreparedRequest.cookies fix #1728Chase Sterling2013-12-041-1/+3
| | | | | Conflicts: requests/sessions.py
* Quote qop values in digest auth.Cory Benfield2013-11-291-2/+2
|
* Fix hangs on streaming uploads with HTTPDigestAuthAkira Kitada2013-11-251-0/+9
| | | | | | | | | | When using Digest Authentication, the client resends the same request after the server responds with the 401 "Unauthorized". However, when doing streaming uploads, it gets stuck because the body data (a file-like object) is already consumed at the initial request. The patch fixes this by rewinding the file-like object before resending the request.
* second commit : Fixed #1623. Added 'MD5-sess' algorithm to HTTPDigestAuthdaftshady2013-10-261-17/+22
|
* Handle case when WWW-Authenticate returns multiple qopsIan Cordasco2013-09-131-3/+3
| | | | | | In Digest Access Authentication there are two possible values (four if you count the not-present and both cases) for authentication. We were narrowly handling one of the four cases. Now we handle two.
* Take advantage of the new copy methodIan Cordasco2013-07-271-7/+1
|
* Make the regular tests passIan Cordasco2013-07-271-10/+12
| | | | I broke Digest Auth completely
* Start work on sending cookies backIan Ross and Ian Cordasco2013-07-271-2/+9
| | | | On 401's the cookies received aren't sent back to the server. See: #1336
* don't replace 'Digest' in digest header valueThomas Weißschuh2013-05-211-1/+1
| | | | See https://github.com/kennethreitz/requests/issues/1358