iOS: authenticate each request by its own header only (no cookies/credential cache)
Two accounts can share one server; the Share Extension's folder listing and the upload sessions now ignore cookies and stored credentials so one account's session can never answer for another. Logs each PROPFIND (user, path, status). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5.5
parent
c2f6e6166d
commit
1542d53a0c
@@ -16,6 +16,10 @@ enum ShareUpload {
|
||||
config.sessionSendsLaunchEvents = true
|
||||
config.isDiscretionary = false
|
||||
config.waitsForConnectivity = true
|
||||
// Authenticate by the request's own header only (see DavClient.session).
|
||||
config.httpShouldSetCookies = false
|
||||
config.httpCookieAcceptPolicy = .never
|
||||
config.urlCredentialStorage = nil
|
||||
return config
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user