mirror of
https://github.com/tahoe-lafs/tahoe-lafs.git
synced 2025-01-03 03:36:44 +00:00
Treat missing Authorization as the same as empty Authorization
This commit is contained in:
parent
f5b24d51e9
commit
920467dcea
@ -100,7 +100,7 @@ def _authorization_decorator(required_secrets):
|
|||||||
@wraps(f)
|
@wraps(f)
|
||||||
def route(self, request, *args, **kwargs):
|
def route(self, request, *args, **kwargs):
|
||||||
if not timing_safe_compare(
|
if not timing_safe_compare(
|
||||||
request.requestHeaders.getRawHeaders("Authorization", [None])[0].encode(
|
request.requestHeaders.getRawHeaders("Authorization", [""])[0].encode(
|
||||||
"utf-8"
|
"utf-8"
|
||||||
),
|
),
|
||||||
swissnum_auth_header(self._swissnum),
|
swissnum_auth_header(self._swissnum),
|
||||||
|
Loading…
Reference in New Issue
Block a user