Fix some errors caused by raising 403 in get_current_user#2919
Merged
gnestor merged 1 commit intojupyter:masterfrom Oct 10, 2017
Merged
Fix some errors caused by raising 403 in get_current_user#2919gnestor merged 1 commit intojupyter:masterfrom
gnestor merged 1 commit intojupyter:masterfrom
Conversation
get_current_user is called in a few places that really shouldn’t raise move the raising to `get_login_url`, which is called in `@web.authenticated`, where we want to replace redirect logic with 403.
minrk
commented
Oct 10, 2017
| 'accept, content-type, authorization, x-xsrftoken') | ||
| self.set_header('Access-Control-Allow-Methods', | ||
| 'GET, PUT, POST, PATCH, DELETE, OPTIONS') | ||
| self.finish() |
Member
Author
There was a problem hiding this comment.
finish is already called on every method, no need to include it explicitly
blink1073
approved these changes
Oct 10, 2017
Contributor
|
Thanks @minrk! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
get_current_user is called in a few places that really shouldn’t raise
move the raising to
get_login_url, which is called in@web.authenticated, where we want to replace redirect logic with 403.@gnestor this fixes a regression in the 5.2 rc (introduced in #2853)