Add RFC 6750 WWW-Authenticate on OAuth bearer APIs
Introduce BearerChallengeMiddleware on MCP, Console and Connect GraphQL, Files, and OAuth2 userinfo. Call sites record challenge intent in context via NoteUnauthenticated, NoteInvalidToken, and NoteInsufficientScope; the middleware applies resource_metadata, invalid_token, and insufficient_scope on WriteHeader. OAuth2 access token middleware flags rejected Bearer tokens for invalid_token challenges. Add Authorizer.ScopesForAction for the scope auth-param. Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
@@ -12,7 +12,8 @@
|
||||
// OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
// PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
// Package bearertoken parses Bearer tokens according to RFC 6750.
|
||||
// Package bearertoken parses Bearer tokens and builds Bearer WWW-Authenticate
|
||||
// challenges according to RFC 6750.
|
||||
//
|
||||
// The grammar is defined as:
|
||||
//
|
||||
@@ -69,6 +70,15 @@ func Parse(credentials string) (string, error) {
|
||||
return token, nil
|
||||
}
|
||||
|
||||
// IsAttempt reports whether credentials use the Bearer scheme.
|
||||
func IsAttempt(credentials string) bool {
|
||||
if len(credentials) < len(scheme) {
|
||||
return false
|
||||
}
|
||||
|
||||
return strings.EqualFold(credentials[:len(scheme)], scheme)
|
||||
}
|
||||
|
||||
// isValidToken checks if the given string is a valid b64token.
|
||||
// A valid b64token consists of 1 or more characters from the set
|
||||
// [A-Za-z0-9-._~+/] followed by zero or more '=' characters.
|
||||
|
||||
Reference in New Issue
Block a user