Authlib Securing Login Endpoint and Passing Identity to Authorized Endpoint

Viewed 25

I am trying to use Python's Authlib package. For that I am defining a login endpoint and an authorized redirect endpoint. I am trying to secure the login endpoint, verify identity and pass it to the authorized endpoint so that tokens can be saved with user's identity.

class GithubLogin(Resource):
  @classmethod
  def get(cls):
    
    response = custom_verify_jwt_in_request(request)
    if response.status_code != 200:
      return {"message": "Unauthorized"}, 401

    redirect_uri = url_for("github.authorize", _external=True, _scheme=os.getenv("URL_SCHEME", "https"))
    return oauth.github.authorize_redirect(redirect_uri, email=response['email'])

class GithubAuthorize(Resource):
  @classmethod
  def get(cls):
    print(request.args)
    # Here I can't find the email parameter I have supplied before the redirect.

Is there a way to handle this case? Preferably without having a dynamic redirect url because apparently it has security flaws.

Thanks!

0 Answers
Related