compare password instead of check_password
This commit is contained in:
parent
366767cd69
commit
ad2b8ab091
1 changed files with 27 additions and 0 deletions
|
|
@ -259,3 +259,30 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
||||||
return False
|
return False
|
||||||
else:
|
else:
|
||||||
return True
|
return True
|
||||||
|
|
||||||
|
def _authenticate_request_body(self, request):
|
||||||
|
"""
|
||||||
|
Try to authenticate the client using client_id and client_secret
|
||||||
|
parameters included in body.
|
||||||
|
|
||||||
|
Remember that this method is NOT RECOMMENDED and SHOULD be limited to
|
||||||
|
clients unable to directly utilize the HTTP Basic authentication scheme.
|
||||||
|
See rfc:`2.3.1` for more details.
|
||||||
|
"""
|
||||||
|
# TODO: check if oauthlib has already unquoted client_id and client_secret
|
||||||
|
try:
|
||||||
|
client_id = request.client_id
|
||||||
|
client_secret = request.client_secret
|
||||||
|
except AttributeError:
|
||||||
|
return False
|
||||||
|
|
||||||
|
if self._load_application(client_id, request) is None:
|
||||||
|
log.debug("Failed body auth: Application %s does not exists" % client_id)
|
||||||
|
return False
|
||||||
|
# TODO: check why not work
|
||||||
|
elif not client_secret == request.client.client_secret:
|
||||||
|
log.debug("Failed body auth: wrong client secret %s" % client_secret)
|
||||||
|
return False
|
||||||
|
else:
|
||||||
|
return True
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue