INNER CODE UNIT · Python
_bearer_matches
MakazhanAlpamys/Soup · src/soup_cli/ui/app.py:350
def _bearer_matches(header_value: str) -> bool:
"""Verify Bearer token against configured token in constant time.
Encodes both values to UTF-8 bytes before comparing, because
secrets.compare_digest raises TypeError if passed non-ASCII str arguments
(e.g. when Starlette decodes header bytes >= 0x80 using Latin-1).
"""
with _auth_token_lock:
expected = f"Bearer {_auth_token}".encode("utf-8")
return secrets.compare_digest(header_value.encode("utf-8"), expected)
def _is_loopback(host: str) -> bool:
"""Return True if host is a loopback address or localhost."""
if host.lower() == "localhost":
return True
try:
return ipaddress.ip_address(host.strip("[]")).is_loopback