compare password instead of check_password

This commit is contained in:
mahdavi 2022-09-28 13:19:11 +03:30
parent 366767cd69
commit ad2b8ab091

View file

@ -259,3 +259,30 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
return False
else:
return True
def _authenticate_request_body(self, request):
"""
Try to authenticate the client using client_id and client_secret
parameters included in body.
Remember that this method is NOT RECOMMENDED and SHOULD be limited to
clients unable to directly utilize the HTTP Basic authentication scheme.
See rfc:`2.3.1` for more details.
"""
# TODO: check if oauthlib has already unquoted client_id and client_secret
try:
client_id = request.client_id
client_secret = request.client_secret
except AttributeError:
return False
if self._load_application(client_id, request) is None:
log.debug("Failed body auth: Application %s does not exists" % client_id)
return False
# TODO: check why not work
elif not client_secret == request.client.client_secret:
log.debug("Failed body auth: wrong client secret %s" % client_secret)
return False
else:
return True