diff --git a/apps/gooyal_oauth2/validators.py b/apps/gooyal_oauth2/validators.py index b4c930e..7153aaf 100755 --- a/apps/gooyal_oauth2/validators.py +++ b/apps/gooyal_oauth2/validators.py @@ -259,3 +259,30 @@ class OAuth2Validator(BaseOAuth2Validator): # pylint: disable=w0223 return False else: return True + + def _authenticate_request_body(self, request): + """ + Try to authenticate the client using client_id and client_secret + parameters included in body. + + Remember that this method is NOT RECOMMENDED and SHOULD be limited to + clients unable to directly utilize the HTTP Basic authentication scheme. + See rfc:`2.3.1` for more details. + """ + # TODO: check if oauthlib has already unquoted client_id and client_secret + try: + client_id = request.client_id + client_secret = request.client_secret + except AttributeError: + return False + + if self._load_application(client_id, request) is None: + log.debug("Failed body auth: Application %s does not exists" % client_id) + return False + # TODO: check why not work + elif not client_secret == request.client.client_secret: + log.debug("Failed body auth: wrong client secret %s" % client_secret) + return False + else: + return True +