Treat missing Authorization as the same as empty Authorization

This commit is contained in:
Jean-Paul Calderone 2022-11-29 10:19:01 -05:00
parent f5b24d51e9
commit 920467dcea

View File

@ -100,7 +100,7 @@ def _authorization_decorator(required_secrets):
@wraps(f)
def route(self, request, *args, **kwargs):
if not timing_safe_compare(
request.requestHeaders.getRawHeaders("Authorization", [None])[0].encode(
request.requestHeaders.getRawHeaders("Authorization", [""])[0].encode(
"utf-8"
),
swissnum_auth_header(self._swissnum),