v1.3.1 - HttpOnly Cookie + AUTO_AUTHORIZE
🎯 HttpOnly Cookie + AUTO_AUTHORIZE - Seamless UX Enhancement
Major breakthrough: Automatic Swagger UI authorization now works with HttpOnly cookies! Based on industry-standard patterns from Azure API Management and enterprise solutions.
✨ New Features
- 🔒 Smart Token Management - One-time token exposure for Swagger UI setup with immediate cleanup
- ⚡ Seamless UX - Login → Auto-authorized Swagger UI (no manual token copying needed)
- 🏗️ Industry-Standard Pattern - Implements secure "one-time token exposure" used by major API tools
- 🔄 Full Compatibility - Works with HttpOnly cookies, localStorage, and sessionStorage modes
🔐 Security Enhancements
- Enhanced HttpOnly Cookie Security - Maintains XSS protection while enabling AUTO_AUTHORIZE
- Smart Token Exposure - swagger_token provided only once during login, immediately cleared from memory
- Zero Security Compromise - HttpOnly cookie remains inaccessible to JavaScript after initial setup
- Backward Compatibility - All existing security features preserved
🔧 Technical Improvements
- Enhanced Views: Added smart swagger_token provision when both USE_HTTPONLY_COOKIE and AUTO_AUTHORIZE are enabled
- JavaScript Optimization: Improved token handling logic with automatic cleanup for security
- Middleware Enhancement: Better cookie-based authentication handling
- Configuration Flexibility: Seamless integration with existing token storage modes
💡 User Experience
- No Manual Steps - Authentication automatically populates Swagger UI authorization
- Immediate Access - Login once, use all API endpoints without re-authentication
- Production Ready - Enterprise-grade security with consumer-friendly UX
- Developer Friendly - Zero configuration changes needed for existing setups
📚 Research Foundation
Based on comprehensive analysis of how industry leaders handle this challenge:
- Azure API Management - One-time token exposure pattern
- Postman/Insomnia - Temporary token access for tool integration
- Enterprise API Tools - Secure automation without compromising HttpOnly cookie security
🚀 Installation
pip install --upgrade drf-spectacular-auth🔧 Configuration
No configuration changes needed! The new functionality works automatically when both settings are enabled:
DRF_SPECTACULAR_AUTH = {
'USE_HTTPONLY_COOKIE': True,
'AUTO_AUTHORIZE': True, # Now works with HttpOnly cookies!
}