I'm assuming it's there to handle expired cookies. On a 401 return code it immediately trys re-establishing a session. If your login is actually incorrect or unauthorized and you're using basic mode auth it seems to result in an endless loop.
I have a simple patch for it applied to my codebase that will break recursion by only trying once more after a 401, in case reauth is required, and will accept a 401 as legitimate on the first attempt when instantiating the session.
Is my understanding about its purpose correct? If so, I'll put in a pull request.
def __init__(self, session, _get_session, auth):
self._session = session
self._get_session = _get_session
self.__auth = auth
# First 401 is real. Others are cookie expiry.
self.__401 = True
def handle_401(self, response, **kwargs):
if response.status_code != 401:
self.__401 = False
return response
# If this is a 401, retry in case cookie expired.
# prevent looping on 401s when we're actually unauth'd
if self.__401:
return response
self.__401 = True
self.init_session()
response = self.process_original_request(response.request.copy())
self.__401 = False
return response