Include WWW-Authenticate headers in @auth_required.

When using @http_auth_required, the WWW-Authenticate header is included,
but when using @auth_required('basic'), it is not. This change includes
that header in every @auth_required call that contains the 'basic'
method.
This commit is contained in:
Nuno Santos
2015-01-30 11:27:53 +01:00
parent c7d0ea9cce
commit 3681823fcf
2 changed files with 20 additions and 3 deletions
+7 -3
View File
@@ -137,11 +137,15 @@ def auth_required(*auth_methods):
def wrapper(fn):
@wraps(fn)
def decorated_view(*args, **kwargs):
mechanisms = [login_mechanisms.get(method) for method in auth_methods]
for mechanism in mechanisms:
h = {}
mechanisms = [(method, login_mechanisms.get(method)) for method in auth_methods]
for method, mechanism in mechanisms:
if mechanism and mechanism():
return fn(*args, **kwargs)
return _get_unauthorized_response()
elif method == 'basic':
r = _security.default_http_auth_realm
h['WWW-Authenticate'] = 'Basic realm="%s"' % r
return _get_unauthorized_response(headers=h)
return decorated_view
return wrapper