extractCredentials
Description
Extracts the potentially present HttpCredentials
HttpCredentials
provided with the request’s Authorization
Authorization
header, which can be then used to implement some custom authentication or authorization logic.
See Credentials and password timing attacks for details about verifying the secret.
Example
- Scala
-
source
val route = extractCredentials { creds => complete { creds match { case Some(c) => "Credentials: " + c case _ => "No credentials" } } } // tests: val johnsCred = BasicHttpCredentials("John", "p4ssw0rd") Get("/") ~> addCredentials(johnsCred) ~> // adds Authorization header route ~> check { responseAs[String] shouldEqual "Credentials: Basic Sm9objpwNHNzdzByZA==" } Get("/") ~> route ~> check { responseAs[String] shouldEqual "No credentials" }
- Java
-
source
import org.apache.pekko.http.javadsl.model.headers.HttpCredentials; import static org.apache.pekko.http.javadsl.server.Directives.complete; import static org.apache.pekko.http.javadsl.server.Directives.extractCredentials; final Route route = extractCredentials( optCreds -> { if (optCreds.isPresent()) { return complete("Credentials: " + optCreds.get()); } else { return complete("No credentials"); } }); // tests: final HttpCredentials johnsCred = BasicHttpCredentials.createBasicHttpCredentials("John", "p4ssw0rd"); testRoute(route) .run(HttpRequest.GET("/").addCredentials(johnsCred)) .assertEntity("Credentials: Basic Sm9objpwNHNzdzByZA=="); testRoute(route).run(HttpRequest.GET("/")).assertEntity("No credentials");
1.0.1