Skip to content

fix(auth): match Bearer scheme case-insensitively - #4187

Open
ericcurtin wants to merge 1 commit into
NVIDIA:mainfrom
ericcurtin:fix/3903-bearer-scheme-case/ericcurtin
Open

ericcurtin wants to merge 1 commit into
NVIDIA:mainfrom
ericcurtin:fix/3903-bearer-scheme-case/ericcurtin

Conversation

@ericcurtin

Copy link
Copy Markdown
Contributor

Summary

The Bearer auth scheme is now matched case-insensitively (RFC 9110), so bearer <t> and BEARER <t> authenticate like Bearer <t>.

Related Issue

Closes #3903

Changes

  • Add openshell_core::auth::strip_bearer_scheme and bearer_credential (server), replacing the duplicated strip_prefix("Bearer ") parsing.
  • Use them in the OIDC, peer, sandbox JWT, compute driver, refresh RPC, sandbox protocol and service routing paths, and in JWT expiry parsing.
  • Drop a redundant second strip in compute_refresh_delay.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable)

cargo fmt, cargo clippy -D warnings and cargo test for openshell-core, openshell-sandbox-backend and openshell-server (auth, service routing; prebuilt-z3). The openshell-core e2fsprogs tests flake on main too.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@ericcurtin

Copy link
Copy Markdown
Contributor Author

@mrunalp PTAL when you get a chance, and /ok to test 9be201b45e6d0e526989e5a4963a5d855ecd78df if it looks good. Thank you!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(auth): Authorization header parsing requires exact-case Bearer and rejects valid bearer scheme

1 participant