From ad2b8ab091b4bc6ebc0c862c2d61bda8c38796fa Mon Sep 17 00:00:00 2001 From: mahdavi Date: Wed, 28 Sep 2022 13:19:11 +0330 Subject: [PATCH] compare password instead of check_password --- apps/gooyal_oauth2/validators.py | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+) diff --git a/apps/gooyal_oauth2/validators.py b/apps/gooyal_oauth2/validators.py index b4c930e..7153aaf 100755 --- a/apps/gooyal_oauth2/validators.py +++ b/apps/gooyal_oauth2/validators.py @@ -259,3 +259,30 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223 return False else: return True + + def _authenticate_request_body(self, request): + """ + Try to authenticate the client using client_id and client_secret + parameters included in body. + + Remember that this method is NOT RECOMMENDED and SHOULD be limited to + clients unable to directly utilize the HTTP Basic authentication scheme. + See rfc:`2.3.1` for more details. + """ + # TODO: check if oauthlib has already unquoted client_id and client_secret + try: + client_id = request.client_id + client_secret = request.client_secret + except AttributeError: + return False + + if self._load_application(client_id, request) is None: + log.debug("Failed body auth: Application %s does not exists" % client_id) + return False + # TODO: check why not work + elif not client_secret == request.client.client_secret: + log.debug("Failed body auth: wrong client secret %s" % client_secret) + return False + else: + return True +