compare password instead of check_password
This commit is contained in:
parent
366767cd69
commit
ad2b8ab091
1 changed files with 27 additions and 0 deletions
|
|
@ -259,3 +259,30 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223
|
|||
return False
|
||||
else:
|
||||
return True
|
||||
|
||||
def _authenticate_request_body(self, request):
|
||||
"""
|
||||
Try to authenticate the client using client_id and client_secret
|
||||
parameters included in body.
|
||||
|
||||
Remember that this method is NOT RECOMMENDED and SHOULD be limited to
|
||||
clients unable to directly utilize the HTTP Basic authentication scheme.
|
||||
See rfc:`2.3.1` for more details.
|
||||
"""
|
||||
# TODO: check if oauthlib has already unquoted client_id and client_secret
|
||||
try:
|
||||
client_id = request.client_id
|
||||
client_secret = request.client_secret
|
||||
except AttributeError:
|
||||
return False
|
||||
|
||||
if self._load_application(client_id, request) is None:
|
||||
log.debug("Failed body auth: Application %s does not exists" % client_id)
|
||||
return False
|
||||
# TODO: check why not work
|
||||
elif not client_secret == request.client.client_secret:
|
||||
log.debug("Failed body auth: wrong client secret %s" % client_secret)
|
||||
return False
|
||||
else:
|
||||
return True
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue