fix: exclude signature from signing string in BoxIMClient
Prevents stale signature values from leaking into the MD5 signing calculation, matching the news_service.py pattern. Adds a test that passes a stale signature in extra params and verifies the returned signature is freshly computed.
This commit is contained in:
@@ -32,6 +32,8 @@ class BoxIMClient:
|
||||
keys = sorted(params.keys())
|
||||
sign_parts = []
|
||||
for k in keys:
|
||||
if k in ("signature", "accessSecret"):
|
||||
continue
|
||||
v = params.get(k)
|
||||
if v and v != "" and v != []:
|
||||
sign_parts.append(f"{k}={v}")
|
||||
|
||||
Reference in New Issue
Block a user