Skip to content

Conversation

@stephendwolff
Copy link
Contributor

I've added the update to run the token validation in the order set in JWT_TOKEN_LOCATION, and this allows a valid token earlier in the list to authenticate the user, and invalid to be ignored if later.

This suits my use case - but perhaps another option could be to require no invalid tokens?

I wrote a couple of tests, and fixed one of the error messages in the existing multiple token location test.

Also, I added a note to the configuration options documentation for JWT_TOKEN_LOCATION

@pep8speaks
Copy link

pep8speaks commented Jul 2, 2019

Hello @stephendwolff! Thanks for updating this PR. We checked the lines you've touched for PEP 8 issues, and found:

There are currently no PEP 8 issues detected in this Pull Request. Cheers! 🍻

Comment last updated at 2019-07-03 15:13:56 UTC

@coveralls
Copy link

coveralls commented Jul 2, 2019

Coverage Status

Coverage remained the same at 100.0% when pulling 35dcbe5 on stephendwolff:master into 854bc2e on vimalloc:master.

Copy link
Owner

@vimalloc vimalloc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One minor thing, otherwise looks great!


# add the functions in the order specified in JWT_TOKEN_LOCATION
for location in locations:
if location == 'cookies' and config.jwt_in_cookies:
Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we can get rid of the config.jwt_in_cookies (et al) from these if statements, as they are doing the same check that we are doing here.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point!

@vimalloc
Copy link
Owner

vimalloc commented Jul 2, 2019

I think the way you have it where if there is a valid token higher up in the token location list supersedes an invalid token later in token location list makes the most sense 👍

@vimalloc vimalloc merged commit e1d51a5 into vimalloc:master Jul 3, 2019
@vimalloc
Copy link
Owner

vimalloc commented Jul 3, 2019

Looks great! Thanks for contributing! I'll get a new version released momentarily.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants