Skip to content

v1.3.1 - HttpOnly Cookie + AUTO_AUTHORIZE

Choose a tag to compare

@CodeMath CodeMath released this 30 Aug 15:47
· 20 commits to main since this release

🎯 HttpOnly Cookie + AUTO_AUTHORIZE - Seamless UX Enhancement

Major breakthrough: Automatic Swagger UI authorization now works with HttpOnly cookies! Based on industry-standard patterns from Azure API Management and enterprise solutions.

✨ New Features

  • 🔒 Smart Token Management - One-time token exposure for Swagger UI setup with immediate cleanup
  • ⚡ Seamless UX - Login → Auto-authorized Swagger UI (no manual token copying needed)
  • 🏗️ Industry-Standard Pattern - Implements secure "one-time token exposure" used by major API tools
  • 🔄 Full Compatibility - Works with HttpOnly cookies, localStorage, and sessionStorage modes

🔐 Security Enhancements

  • Enhanced HttpOnly Cookie Security - Maintains XSS protection while enabling AUTO_AUTHORIZE
  • Smart Token Exposure - swagger_token provided only once during login, immediately cleared from memory
  • Zero Security Compromise - HttpOnly cookie remains inaccessible to JavaScript after initial setup
  • Backward Compatibility - All existing security features preserved

🔧 Technical Improvements

  • Enhanced Views: Added smart swagger_token provision when both USE_HTTPONLY_COOKIE and AUTO_AUTHORIZE are enabled
  • JavaScript Optimization: Improved token handling logic with automatic cleanup for security
  • Middleware Enhancement: Better cookie-based authentication handling
  • Configuration Flexibility: Seamless integration with existing token storage modes

💡 User Experience

  • No Manual Steps - Authentication automatically populates Swagger UI authorization
  • Immediate Access - Login once, use all API endpoints without re-authentication
  • Production Ready - Enterprise-grade security with consumer-friendly UX
  • Developer Friendly - Zero configuration changes needed for existing setups

📚 Research Foundation

Based on comprehensive analysis of how industry leaders handle this challenge:

  • Azure API Management - One-time token exposure pattern
  • Postman/Insomnia - Temporary token access for tool integration
  • Enterprise API Tools - Secure automation without compromising HttpOnly cookie security

🚀 Installation

pip install --upgrade drf-spectacular-auth

🔧 Configuration

No configuration changes needed! The new functionality works automatically when both settings are enabled:

DRF_SPECTACULAR_AUTH = {
    'USE_HTTPONLY_COOKIE': True,
    'AUTO_AUTHORIZE': True,  # Now works with HttpOnly cookies!
}