For my app, I manage session data on the server in a database with help form flask_session.
I want to modify behaviour so that a session is only created if the remote address is not on an IP blacklist.
I've amended SessionInterface's open_session to include the following:
self.firewall = Firewall # flask_sqlalchemy model
def open_session(self, app, request):
firewall = self.firewall.query.filter_by(ip_address=request.remote_addr).first()
if firewall and firewall.black_list:
abort(400)
...
To mark up to nicer errors, I create error handlers:
@main.app_errorhandler(400)
def bad_request(e):
return render_template("400.html"),400
The database firewall lookup works, and the abort(400) is called as expected.
The problem is the abort call from the open_session does not trigger the use of the template. When an abort is called from any blueprint view linked to the app, it does use the template.
How can I force the use of the abort template I have prepared from the open_session?