refactor: move basic auth credentials out of Request #2164
Merged
Merged
Conversation
This reverts commit da8d83f.
the basic auth extractor is now held by WebsiteChecker which makes sense because it's only applicable to website checks. previously, the basic auth credentials were attached to the Request during the collecting phase, which is unnecessarily early i think.
thomas-zahner
approved these changes
May 8, 2026
thomas-zahner
left a comment
Member
There was a problem hiding this comment.
Looks like a nice little improvement!
@mre any objections?
mre
approved these changes
May 9, 2026
mre
left a comment
Member
There was a problem hiding this comment.
Looks fine. If we like, we can rename it, but we can do that in a follow-up PR. ✌️
Closed
This was referenced May 30, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
the basic auth extractor is now held by WebsiteChecker which makes sense because it's only applicable to website checks.
previously, the basic auth credentials were attached to the Request during the collecting phase, which is unnecessarily early i think. this change also avoids the need to repeatedly pass the "basic auth extractor" into helper functions.
i should add that i find the basic auth extractor and basic auth selector names to be very confusing. to me, "basic auth extractor" sounds like it parses basic auth strings from URLs when it's actually just a known database of basic auth credentials. "basic auth selector" sounds like it should do what basic auth extract actually does - select from a list of known basic auths. i haven't changed it in this PR but just something to think about.
One goal of this refactor is to make it more palatable to store Request inside Response (for #2097), since it no longer has sensitive information.