Repository navigation
fix(auth): tell a token-less request to an OIDC deployment to send a token - #1058
Merged
Merged
Conversation
…token With OIDC_ISSUER set and no API key configured, a request without a bearer token fell through to the API-key path and was answered 'api key not configured'. That deployment has no API key to configure. The reason now asks for a bearer token; status and code are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
yeongseon
approved these changes
Oct 6, 2026
yeongseon
left a comment
Collaborator
There was a problem hiding this comment.
authenticate() 전체를 읽고 승인합니다.
- 새 분기는 dev-mode 와 Bearer 경로 뒤, API 키 경로 앞에 있고, 조건이 "OIDC 가 켜져 있고 API 키가 설정되지 않음" 입니다. 그 조건에서 종전 경로는
_verify_api_key의 첫 줄(api key not configured)에서 끝났으므로, 바뀌는 것은 문구뿐이고 통과하던 요청이 막히거나 막히던 요청이 통과하는 경우는 없습니다. AuthError의code는 기본값 그대로(unauthorized)이고 테스트가 그것을 봅니다.- 부정 2건(키도 받는 배포, OIDC 없는 배포)이 종전 답을 고정합니다.
인증 응답이라 직접 머지하지 않고 리뷰를 기다린 판단이 맞습니다.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
무엇을
OIDC_ISSUER가 설정되고KPUBDATA_BUILDER_API_KEY가 없는 배포(다중 사용자 프로필)에서, 토큰 없는 요청의 401 문구를 고칩니다.{"error": "api key not configured", "code": "unauthorized"}{"error": "sign-in required: send a bearer token", "code": "unauthorized"}왜
#1057 의 기동 스모크를 손으로 띄워 보다가 봤습니다. 그 배포에는 설정할 API 키가 없는데, 문구는 읽는 사람을 키 설정 쪽으로 보냅니다.
authenticate()가 Bearer 가 없으면 그대로 API 키 경로로 내려가기 때문입니다.바뀌지 않는 것
code(unauthorized). Studio 는code로 분기합니다. 문구에 의존하는 곳은 Builder 계약·테스트·문서와 Studiosrc에서 찾지 못했습니다(grep "api key not configured").api key not configured그대로.테스트
tests/unit/test_oidc_auth.py::TestRequestWithoutAToken4건 — OIDC 전용에서 새 문구, API 키를 보내도 같은 답, 부정 2건(키도 받는 배포 / OIDC 없는 배포는 종전대로).검증
test_oidc_auth.py,test_auth_throttle.py,test_signup_ledger.py,test_ephemeral_credentials.py124건 통과ruff,mypy src통과인증 응답의 문구를 바꾸는 것이라 직접 머지하지 않고 리뷰를 기다립니다.
🤖 Generated with Claude Code