Skip to content

server/auth: accept bearer-prefixed auth tokens#21910

Open
sahilpatel09 wants to merge 1 commit into
etcd-io:mainfrom
sahilpatel09:bearer-prefixed-auth
Open

server/auth: accept bearer-prefixed auth tokens#21910
sahilpatel09 wants to merge 1 commit into
etcd-io:mainfrom
sahilpatel09:bearer-prefixed-auth

Conversation

@sahilpatel09
Copy link
Copy Markdown
Contributor

@sahilpatel09 sahilpatel09 commented Jun 4, 2026

Solves #19752

Basically, when clients pass the token prefixed with string "Bearer " this error is thrown

Error: auth: invalid auth token

as the auth only expects raw token strings. The fix strips the "Bearer " prefix if it is part of the token, making bearer-prefixed tokens authenticate the same way as raw tokens.

Signed-off-by: Sahil Patel <smppatel999@gmail.com>
@k8s-ci-robot
Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: sahilpatel09
Once this PR has been reviewed and has the lgtm label, please assign serathius for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot
Copy link
Copy Markdown

Hi @sahilpatel09. Thanks for your PR.

I'm waiting for a etcd-io member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Tip

We noticed you've done this a few times! Consider joining the org to skip this step and gain /lgtm and other bot rights. We recommend asking approvers on your previous PRs to sponsor you.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@sahilpatel09
Copy link
Copy Markdown
Contributor Author

cc @ahrtr

@ahrtr
Copy link
Copy Markdown
Member

ahrtr commented Jun 7, 2026

/ok-to-test

cc @fuweid @ivanvc @serathius

@codecov
Copy link
Copy Markdown

codecov Bot commented Jun 7, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 69.79%. Comparing base (7d330a1) to head (43a4c4e).
⚠️ Report is 24 commits behind head on main.

Additional details and impacted files
Files with missing lines Coverage Δ
server/auth/store.go 87.11% <100.00%> (ø)

... and 27 files with indirect coverage changes

@@            Coverage Diff             @@
##             main   #21910      +/-   ##
==========================================
- Coverage   69.79%   69.79%   -0.01%     
==========================================
  Files         449      449              
  Lines       38208    38208              
==========================================
- Hits        26667    26666       -1     
- Misses      10114    10115       +1     
  Partials     1427     1427              

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 7d330a1...43a4c4e. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

3 participants