Restore UA-aware auth header advertisement
Revert accidental removal of WWW-Authenticate headers. Windows WebDAV clients receive Basic + Negotiate; all other clients receive Basic only.
This commit is contained in:
+8
-1
@@ -279,7 +279,14 @@ def _log_webdav_user_agent_once(request, user_agent: str):
|
||||
|
||||
|
||||
def _build_ua_auth_headers(request, *, include_hint=False) -> dict[str, str]:
|
||||
return {}
|
||||
user_agent = request.headers.get("user-agent", "")
|
||||
_log_webdav_user_agent_once(request, user_agent)
|
||||
if _is_windows_auth_client(user_agent):
|
||||
challenge = f'Basic realm="{_AUTH_REALM}", Negotiate'
|
||||
else:
|
||||
challenge = f'Basic realm="{_AUTH_REALM}"'
|
||||
headers = {"WWW-Authenticate": challenge}
|
||||
return headers
|
||||
|
||||
|
||||
def _cleanup_ntlm_challenges():
|
||||
|
||||
@@ -159,11 +159,11 @@ async def test_options_unauthenticated_allowed(client):
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_unauthenticated_sends_no_auth_challenge(client):
|
||||
async def test_unauthenticated_sends_basic_auth_challenge(client):
|
||||
_, res = await client.request("PROPFIND", "/files/")
|
||||
|
||||
assert res.status_code == 401
|
||||
assert "www-authenticate" not in res.headers
|
||||
assert res.headers.get("www-authenticate", "").lower().startswith('basic realm="cista"')
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
|
||||
Reference in New Issue
Block a user