CherryPy broken Basic-Auth (for non-ISO-8859-1 strings) - Fix stuck with attempt of a library clean-up
Paul Jaros <[email protected]> Wed, 18 Apr 2018 02:05:55 -0700 (PDT)
| Newsgroups | gmane.comp.python.cherrypy |
|---|---|
| Message-ID | <[email protected]> |
Hello I'm using CherryPy @work and found out that there is a problem when a browser sends their Basic-Auth string encoded in UTF-8. I've documented the behaviour on Stackoverflow <https://stackoverflow.com/questions/48009727/cherrypy-allways-decodes-basic-auth-with-iso-8859-1>and opend a Github Issue <https://github.com/cherrypy/cherrypy/issues/1680>. Everthing felt like we could work out the issue, until it was found there was a duplicate authentication modul <https://github.com/cherrypy/cherrypy/issues/1688> which needs some merging and deprecating first. After a month of further changes, both efforts have come to a full stop. Now two addional months later there have been no progress on any of those two issues. I know this is opensource. I know that, generally speaking, I can create my own branch and fix it to my liking. I'm willing to provide improvements, but I have no clue what the master-plan for the de-duplication of the authentication module is and thus don't know how to help there, I have my supriors asking how/if this issue is progessing and I can't give them a good answer. Right now I'm considering of switching framework because I fear that this is issue will never be fixed or that it will emerge to late to be useful. *My question:* Did I miss anything? Are there any options I've missed? Did anybody had similar issues? -- You received this message because you are subscribed to the Google Groups "cherrypy-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to cherrypy-users+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected] To post to this group, send email to cherrypy-users-/JYPxA39Uh5TLH3MbocFF+G/[email protected] Visit this group at https://groups.google.com/group/cherrypy-users. For more options, visit https://groups.google.com/d/optout.