Skip to content

0.4.0: remove SessionConfig.use_bearer_token in favour of token_source_priority #377

Description

@allen0099

Problem

There are two ways to turn off Authorization: Bearer tokens: SessionConfig(use_bearer_token=False), or leaving "bearer" out of token_source_priority. _read_header_token checks both. Once #75 makes token_source_priority the single list of token sources (header, bearer, cookie), the boolean only duplicates it.

Plan

  • 0.3.9: SessionConfig emits a DeprecationWarning when use_bearer_token is passed explicitly, True or False. The message names the replacement:
    • use_bearer_token=True: drop the argument, since it is the default.
    • use_bearer_token=False: leave "bearer" out of token_source_priority, keeping "cookie" in the list (see Allow cookies in token_source_priority #75).
  • 0.4.0: remove the field. Bearer tokens are read if and only if "bearer" is in token_source_priority.
  • Update the migration guide table and section, the changelog fragment, docs/SESSION.md and the zh-TW mirrors.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    breaking-changeChanges public behaviour or API; needs a minor/major releasesessionSession management subsystem

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions