Add user:pass Basic auth mode for API-key connectors
The API-key connection transport could present a key as a Bearer token, an x-api-key header, a custom scheme (SSWS/Token), or HTTP Basic with an empty password (Cursor). None of these can carry a real password, which providers such as ClickHouse Cloud (keyId:keySecret) and Langfuse (publicKey:secretKey) require. Add a fourth mode, APIKeyBasicAuthUserPass, that base64-encodes the stored "username:password" credential verbatim into Authorization: Basic. SetBasicAuth cannot express this -- it re-appends a ":" and corrupts the credential. The mode is wired generically through the registry and the create-connector resolver and is mutually exclusive with the other API-key auth modes. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
@@ -109,6 +109,20 @@ func TestRegistry_Register(t *testing.T) {
|
||||
assert.Contains(t, err.Error(), "mutually exclusive")
|
||||
})
|
||||
|
||||
t.Run("APIKeyBasicAuthUserPass and APIKeyHeader mutually exclusive", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
r := provider.NewRegistry()
|
||||
err := r.Register(&provider.Registration{
|
||||
Provider: coredata.ConnectorProviderSlack,
|
||||
DisplayName: "Slack",
|
||||
APIKeyBasicAuthUserPass: true,
|
||||
APIKeyHeader: "x-api-key",
|
||||
})
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), "mutually exclusive")
|
||||
})
|
||||
|
||||
t.Run("BuildTokenURLForDomain and BuildTokenURLForSite mutually exclusive", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user