edicl / drakma

HTTP client written in Common Lisp
http://edicl.github.io/drakma/
248 stars 58 forks source link

Remove Authorization: header on redirect. #102

Closed rwiker closed 4 years ago

rwiker commented 4 years ago

Most clients strip the Authorization header on redirects, for security reasons.

There is a recent IETF draft concerning redirects and authorization (https://tools.ietf.org/html/draft-williams-http-accept-auth-and-redirect-00) that should probably be included in future work on Drakma.