Repository navigation
Forbid requests whose token has no subject claim, instead of failing with 500 - #5984
Draft
ramonsmits wants to merge 1 commit into
Draft
ramonsmits wants to merge 1 commit into
ramonsmits wants to merge 1 commit into
Conversation
…g with 500 With role-based authorization enabled, PermissionVerbHandler needs the subject ID and subject name claims for the authorization audit log. When a token did not have one of them, the handler threw an InvalidOperationException, and every request with that token got 500. The handler now denies the request (403) and logs a warning that names the missing claim and the setting that configures it. - Remove ClaimsPrinicpalExtensionMethods.RequireClaim. The handler was its only caller. - New tests: an admin token without sub or preferred_username is denied every permission.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With role-based authorization enabled, a token without the subject ID claim (
sub) or the subject name claim (preferred_username) gets500 Internal Server Erroron every API request. The authorization handler throws because the audit log needs both values. The handler now denies the request with403 Forbidden, and logs a warning that names the missing claim and the setting that configures it.PermissionVerbHandlerfails the requirement and logs a warning, instead of throwing.ClaimsPrinicpalExtensionMethods.RequireClaim. The handler was its only caller.suborpreferred_usernameis denied every permission.