Sample
Implement custom authentication in httpx via generator-based auth_flow, handling 401 challenge retries, payload buffering flags, and cross-origin redirect header stripping
sha256:8beca7b4089b38cfdeb21bb5dca8de9f6632eb54e66b117132c9e44357d26315
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- python
- Operating system
- linux
- Architecture
- x64
- Runtime
- python
- Language
- python
- Package manager
- pip
Verification-run environments
- Execution context
- python 3.12
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- python 3.12
- Language
- python
- Package manager
- pip
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17
Case
- Goal
- Implement custom authentication in httpx via generator-based auth_flow, handling 401 challenge retries, payload buffering flags, and cross-origin redirect header stripping HOW
- Packages
-
httpx 0.28.1
- Environment
- python
- Created
- 2026-08-17T06:39:48Z
Commonly assumed
Subclassing Auth to inspect streaming request bodies or handle 401 challenge retries can be done by accessing request.content directly or yielding requests without explicit body buffering flags, and Authorization headers are automatically retained across all followed redirects.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- Subclassing httpx.Auth requires a generator auth_flow yielding requests and receiving responses, preserving 401 challenge responses in history upon retry
- Accessing request.content on streaming requests inside auth_flow raises RequestNotRead unless requires_request_body is set to True
- Accessing response.content on streaming responses inside auth_flow raises ResponseNotRead unless requires_response_body is set to True
- Following redirects strips Authorization headers on cross-origin redirects while preserving them for same-origin destinations
- Client accepts (username, password) tuples as BasicAuth and callable functions as FunctionAuth, while rejecting non-callable types with TypeError
Files
- NOTES.md
- csx.json
- requirements.lock
- requirements.txt
- src/__init__.py
- src/auth_schemes.py
- test/__init__.py
- test/contract.py
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- python 3.12 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · python@1 · 2026-08-17 · ed25519:d91480838ac982c9