I have been trying for some time now to use a login form, create a JWT with Flask-JWT-Extended and then pass it along with a redirect if it passes the checks.
Very simple example below, but I'm getting "No Authorization Header" in return, which makes me think it won't pass the header which is set? I want to protect a view which will render a template if the auth is ok.
@app.route("/")
def index():
return render_template("index.html")
@app.route('/login', methods=['POST'])
def login():
username = request.form["username"]
password = request.form["password"]
if not username:
return jsonify({"msg": "Missing username parameter"}), 400
if not password:
return jsonify({"msg": "Missing password parameter"}), 400
if username != 'test' or password != 'test!':
return jsonify({"msg": "Bad username or password"}), 401
access_token = create_access_token(identity=username)
response = redirect('http://127.0.0.1:5000/protected')
response.headers["Authorization"] = f'Bearer {access_token}'
return response
@app.route('/protected', methods=['GET'])
@jwt_required
def protected():
current_user = get_jwt_identity()
return jsonify(logged_in_as=current_user), 200