@@ -141,20 +141,21 @@ def test_redirect_cross_host_remove_headers(self):
141
141
"GET" ,
142
142
"%s/redirect" % self .base_url ,
143
143
fields = {"target" : "%s/headers" % self .base_url_alt },
144
- headers = {"Authorization" : "foo" },
144
+ headers = {"Authorization" : "foo" , "Cookie" : "foo=bar" },
145
145
)
146
146
147
147
assert r .status == 200
148
148
149
149
data = json .loads (r .data .decode ("utf-8" ))
150
150
151
151
assert "Authorization" not in data
152
+ assert "Cookie" not in data
152
153
153
154
r = http .request (
154
155
"GET" ,
155
156
"%s/redirect" % self .base_url ,
156
157
fields = {"target" : "%s/headers" % self .base_url_alt },
157
- headers = {"authorization" : "foo" },
158
+ headers = {"authorization" : "foo" , "cookie" : "foo=bar" },
158
159
)
159
160
160
161
assert r .status == 200
@@ -163,14 +164,16 @@ def test_redirect_cross_host_remove_headers(self):
163
164
164
165
assert "authorization" not in data
165
166
assert "Authorization" not in data
167
+ assert "cookie" not in data
168
+ assert "Cookie" not in data
166
169
167
170
def test_redirect_cross_host_no_remove_headers (self ):
168
171
with PoolManager () as http :
169
172
r = http .request (
170
173
"GET" ,
171
174
"%s/redirect" % self .base_url ,
172
175
fields = {"target" : "%s/headers" % self .base_url_alt },
173
- headers = {"Authorization" : "foo" },
176
+ headers = {"Authorization" : "foo" , "Cookie" : "foo=bar" },
174
177
retries = Retry (remove_headers_on_redirect = []),
175
178
)
176
179
@@ -179,14 +182,19 @@ def test_redirect_cross_host_no_remove_headers(self):
179
182
data = json .loads (r .data .decode ("utf-8" ))
180
183
181
184
assert data ["Authorization" ] == "foo"
185
+ assert data ["Cookie" ] == "foo=bar"
182
186
183
187
def test_redirect_cross_host_set_removed_headers (self ):
184
188
with PoolManager () as http :
185
189
r = http .request (
186
190
"GET" ,
187
191
"%s/redirect" % self .base_url ,
188
192
fields = {"target" : "%s/headers" % self .base_url_alt },
189
- headers = {"X-API-Secret" : "foo" , "Authorization" : "bar" },
193
+ headers = {
194
+ "X-API-Secret" : "foo" ,
195
+ "Authorization" : "bar" ,
196
+ "Cookie" : "foo=bar" ,
197
+ },
190
198
retries = Retry (remove_headers_on_redirect = ["X-API-Secret" ]),
191
199
)
192
200
@@ -196,12 +204,17 @@ def test_redirect_cross_host_set_removed_headers(self):
196
204
197
205
assert "X-API-Secret" not in data
198
206
assert data ["Authorization" ] == "bar"
207
+ assert data ["Cookie" ] == "foo=bar"
199
208
200
209
r = http .request (
201
210
"GET" ,
202
211
"%s/redirect" % self .base_url ,
203
212
fields = {"target" : "%s/headers" % self .base_url_alt },
204
- headers = {"x-api-secret" : "foo" , "authorization" : "bar" },
213
+ headers = {
214
+ "x-api-secret" : "foo" ,
215
+ "authorization" : "bar" ,
216
+ "cookie" : "foo=bar" ,
217
+ },
205
218
retries = Retry (remove_headers_on_redirect = ["X-API-Secret" ]),
206
219
)
207
220
@@ -212,6 +225,7 @@ def test_redirect_cross_host_set_removed_headers(self):
212
225
assert "x-api-secret" not in data
213
226
assert "X-API-Secret" not in data
214
227
assert data ["Authorization" ] == "bar"
228
+ assert data ["Cookie" ] == "foo=bar"
215
229
216
230
def test_redirect_without_preload_releases_connection (self ):
217
231
with PoolManager (block = True , maxsize = 2 ) as http :
0 commit comments