Commit 1aa6c93
return a 401 instead of a 500 when a token is rejected
liboauth2 up to 2.3.0 does not set the "status_code" out-parameter of
oauth2_token_verify for a failure it detects locally, i.e. for any JWT that is
expired, carries a bad signature or fails "iss"/"aud"/"nbf" validation. It then
keeps the 0 it was initialized with, which is returned here as an Apache return
code and thus means OK; with no user set Apache logs "AH00027: No
authentication done but request not allowed without authentication" and returns
a 500. An introspection endpoint answering "active": false similarly left the
200 of that successful call behind.
Invert the test so that no non-error status can escape: only a 5xx is relayed
as-is, anything else results in a 401 with a WWW-Authenticate header, as it did
before 4.1.0 started leveraging the status code.
liboauth2 >= 2.3.1 sets the status code itself, but keeping the check here also
covers the older versions that are already packaged.
closes #94
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent e67fb4e commit 1aa6c93
2 files changed
Lines changed: 25 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
1 | 13 | | |
2 | 14 | | |
3 | 15 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
114 | 114 | | |
115 | 115 | | |
116 | 116 | | |
117 | | - | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
118 | 125 | | |
119 | | - | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
120 | 131 | | |
121 | | - | |
122 | | - | |
123 | 132 | | |
124 | 133 | | |
125 | 134 | | |
| |||
0 commit comments