I discovered this issue today while using Fiddler to debug my OAuth connection.
Each requests.Session object has a self.verify attribute stating if SSL certificates should be verified (for example to reject self-signed certificates).
Unfortunately, even if I set the attribute to False on an OAuth2Session object, this flag is not honoured because the default value is True (and not None) in fetch_token and refresh_token.
Note: it does not seem to happen with OAuth1Session objects.
I can provide a PR to fix this, it is extremely easy.
I discovered this issue today while using Fiddler to debug my OAuth connection.
Each
requests.Sessionobject has aself.verifyattribute stating if SSL certificates should be verified (for example to reject self-signed certificates).Unfortunately, even if I set the attribute to
Falseon anOAuth2Sessionobject, this flag is not honoured because the default value isTrue(and notNone) infetch_tokenandrefresh_token.Note: it does not seem to happen with
OAuth1Sessionobjects.I can provide a PR to fix this, it is extremely easy.