-
-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Labels
bugSomething isn't workingSomething isn't working
Description
According to https://datatracker.ietf.org/doc/html/rfc7617#autoid-3 , specification of the realm parameter is REQUIRED, so making realm optional here
fastapi/fastapi/security/http.py
Line 195 in 643d284
| unauthorized_headers = {"WWW-Authenticate": "Basic"} |
and at related places, is misleading and makes it easy to create non-conforming APIs. It bit me when a Shelly device refused (rightfully) to authenticate against the API which was using the default (missing) realm behavior.
wldoooon
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working