Skip to content

Fix uploader auth session cookie support - #1

Merged
Zkh-dot merged 2 commits into
letovo-dev:mainfrom
ya-yara:fix/uploader-auth-session-cookie
Jun 29, 2026
Merged

Fix uploader auth session cookie support#1
Zkh-dot merged 2 commits into
letovo-dev:mainfrom
ya-yara:fix/uploader-auth-session-cookie

Conversation

@ya-yara

@ya-yara ya-yara commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • accept the new HttpOnly AuthSession cookie in the Flask uploader auth check
  • keep legacy Bearer header support
  • forward auth to /letovo-api/auth/amiuploader instead of leaking/requiring a bearer token
  • stop returning tokens in 403 bodies

Tests

  • pytest -q test_flask_uploader_auth.py

@Zkh-dot
Zkh-dot merged commit 388f137 into letovo-dev:main Jun 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants