Skip to content

fix(auth): tell a token-less request to an OIDC deployment to send a token - #1058

Merged
yeongseon merged 1 commit into
mainfrom
fix/oidc-missing-token-reason
Oct 6, 2026
Merged

yeongseon merged 1 commit into
mainfrom
fix/oidc-missing-token-reason

Conversation

@Eomdahyeon

Copy link
Copy Markdown
Collaborator

무엇을

OIDC_ISSUER 가 설정되고 KPUBDATA_BUILDER_API_KEY 가 없는 배포(다중 사용자 프로필)에서, 토큰 없는 요청의 401 문구를 고칩니다.

  • 전: {"error": "api key not configured", "code": "unauthorized"}
  • 후: {"error": "sign-in required: send a bearer token", "code": "unauthorized"}

왜

#1057 의 기동 스모크를 손으로 띄워 보다가 봤습니다. 그 배포에는 설정할 API 키가 없는데, 문구는 읽는 사람을 키 설정 쪽으로 보냅니다. authenticate() 가 Bearer 가 없으면 그대로 API 키 경로로 내려가기 때문입니다.

바뀌지 않는 것

  • 상태 코드(401)와 code(unauthorized). Studio 는 code 로 분기합니다. 문구에 의존하는 곳은 Builder 계약·테스트·문서와 Studio src 에서 찾지 못했습니다(grep "api key not configured").
  • OIDC 와 API 키를 함께 쓰는 배포: 키 경로가 그대로 판정합니다.
  • OIDC 가 없는 배포: api key not configured 그대로.
  • 인증 실패 집계(fix(auth): throttle clients behind a named proxy separately, and do not count expired tokens #1035)에는 손대지 않았습니다.

테스트

tests/unit/test_oidc_auth.py::TestRequestWithoutAToken 4건 — OIDC 전용에서 새 문구, API 키를 보내도 같은 답, 부정 2건(키도 받는 배포 / OIDC 없는 배포는 종전대로).

검증

  • test_oidc_auth.py, test_auth_throttle.py, test_signup_ledger.py, test_ephemeral_credentials.py 124건 통과
  • ruff, mypy src 통과
  • 전체 단위 스위트는 로컬에서 돌리지 않았습니다. CI 에 맡깁니다.

인증 응답의 문구를 바꾸는 것이라 직접 머지하지 않고 리뷰를 기다립니다.

🤖 Generated with Claude Code

…token

With OIDC_ISSUER set and no API key configured, a request without a
bearer token fell through to the API-key path and was answered
'api key not configured'. That deployment has no API key to configure.
The reason now asks for a bearer token; status and code are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@yeongseon yeongseon left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

authenticate() 전체를 읽고 승인합니다.

  • 새 분기는 dev-mode 와 Bearer 경로 뒤, API 키 경로 앞에 있고, 조건이 "OIDC 가 켜져 있고 API 키가 설정되지 않음" 입니다. 그 조건에서 종전 경로는 _verify_api_key 의 첫 줄(api key not configured)에서 끝났으므로, 바뀌는 것은 문구뿐이고 통과하던 요청이 막히거나 막히던 요청이 통과하는 경우는 없습니다.
  • AuthError 의 code 는 기본값 그대로(unauthorized)이고 테스트가 그것을 봅니다.
  • 부정 2건(키도 받는 배포, OIDC 없는 배포)이 종전 답을 고정합니다.

인증 응답이라 직접 머지하지 않고 리뷰를 기다린 판단이 맞습니다.

@yeongseon
yeongseon merged commit 866d488 into main Oct 6, 2026
22 checks passed
@yeongseon
yeongseon deleted the fix/oidc-missing-token-reason branch October 7, 2026 22:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants