Repository navigation
oauthex: accept token68 challenges in WWW-Authenticate - #1357
Open
akshita317 wants to merge 1 commit into
Open
akshita317 wants to merge 1 commit into
akshita317 wants to merge 1 commit into
Conversation
A challenge carries either auth-params or a token68 (RFC 9110, section 11.6.1), as in WWW-Authenticate: Negotiate oYH1MIHyoAMKAQ, Bearer resource_metadata="..." parseSingleChallenge only understood auth-params. A token68 without padding failed with "expected key=value", which made ParseWWWAuthenticate fail the whole header, so the auth handlers never saw the Bearer challenge next to it. A token68 with padding, such as dGVzdA==, was misread as a parameter named "dgvzda". Recognize a token68 and return the challenge without parameters. The "Bearer realm=" test case is removed: "realm=" is a valid token68, and a parameter with no value is still covered by the case "malformed param - no value before comma". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A challenge carries either auth-params or a token68 (RFC 9110, section 11.6.1); the grammar is quoted in the doc comment of
parseSingleChallenge, but only auth-params were handled. Withthe Negotiate challenge failed with
expected key=value,ParseWWWAuthenticatefailed the whole header, and the auth handlers never saw the Bearer challenge. A token68 with padding, such asBasic dGVzdA==, did not fail but was misread as a parameter nameddgvzdawith value=.This recognizes a token68 and returns the challenge with no
Params;Challengehas nowhere to store the token and the SDK only needs Bearer parameters, so it is not kept. TheParamsdoc notes this.Test changes:
TestParseSingleChallenge(token68, token68 with padding, malformed token68) andTestParseWWWAuthenticateToken68(Negotiate next to Bearer). Both fail without the change.Bearer realm="no value" case:realm=is a valid token68. A parameter with no value is still covered by "malformed param - no value before comma".This touches the same file as #1351; whichever lands second will need a trivial rebase.
AI assistance: prepared with Claude Code.