fastapi-auth-middleware icon indicating copy to clipboard operation
fastapi-auth-middleware copied to clipboard

Middleware verify_header method runs even for 404 Not Found routes

Open ermiyaeskandary opened this issue 1 month ago • 0 comments

In my verify_header route, I may be making relatively costly DB calls, HTTP calls etc.

The middleware still runs for 404 requests, resulting in an indirect Denial of Service attack being possible against the remote resource.

It should not run when there are requests that would result in a 404.

ermiyaeskandary avatar Jan 04 '25 23:01 ermiyaeskandary