Skip to content

Commit 1ef1851

Browse files
committed
Fix API status code for unauthorized requests
References issue #1095 Signed-off-by: Igor Zibarev <[email protected]>
1 parent 1b405d4 commit 1ef1851

File tree

3 files changed

+71
-9
lines changed

3 files changed

+71
-9
lines changed

go.sum

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -54,8 +54,6 @@ github.com/Microsoft/hcsshim v0.8.9/go.mod h1:5692vkUqntj1idxauYlpoINNKeqCiG6Sg3
5454
github.com/Microsoft/hcsshim v0.8.14/go.mod h1:NtVKoYxQuTLx6gEq0L96c9Ju4JbRJ4nY2ow3VK6a9Lg=
5555
github.com/Microsoft/hcsshim v0.8.15/go.mod h1:x38A4YbHbdxJtc0sF6oIz+RG0npwSCAvn69iY6URG00=
5656
github.com/Microsoft/hcsshim v0.8.16/go.mod h1:o5/SZqmR7x9JNKsW3pu+nqHm0MF8vbA+VxGOoXdC600=
57-
github.com/Microsoft/hcsshim v0.8.18 h1:cYnKADiM1869gvBpos3YCteeT6sZLB48lB5dmMMs8Tg=
58-
github.com/Microsoft/hcsshim v0.8.18/go.mod h1:+w2gRZ5ReXQhFOrvSQeNfhrYB/dg3oDwTOcER2fw4I4=
5957
github.com/Microsoft/hcsshim v0.8.21 h1:btRfUDThBE5IKcvI8O8jOiIkujUsAMBSRsYDYmEi6oM=
6058
github.com/Microsoft/hcsshim v0.8.21/go.mod h1:+w2gRZ5ReXQhFOrvSQeNfhrYB/dg3oDwTOcER2fw4I4=
6159
github.com/Microsoft/hcsshim/test v0.0.0-20201218223536-d3e5debf77da/go.mod h1:5hlzMzRKMLyo42nCZ9oml8AdTlq/0cvIaBv6tK1RehU=
@@ -148,8 +146,6 @@ github.com/containerd/containerd v1.5.0-beta.3/go.mod h1:/wr9AVtEM7x9c+n0+stptlo
148146
github.com/containerd/containerd v1.5.0-beta.4/go.mod h1:GmdgZd2zA2GYIBZ0w09ZvgqEq8EfBp/m3lcVZIvPHhI=
149147
github.com/containerd/containerd v1.5.0-rc.0/go.mod h1:V/IXoMqNGgBlabz3tHD2TWDoTJseu1FGOKuoA4nNb2s=
150148
github.com/containerd/containerd v1.5.1/go.mod h1:0DOxVqwDy2iZvrZp2JUx/E+hS0UNTVn7dJnIOwtYR4g=
151-
github.com/containerd/containerd v1.5.5 h1:q1gxsZsGZ8ddVe98yO6pR21b5xQSMiR61lD0W96pgQo=
152-
github.com/containerd/containerd v1.5.5/go.mod h1:oSTh0QpT1w6jYcGmbiSbxv9OSQYaa88mPyWIuU79zyo=
153149
github.com/containerd/containerd v1.5.7 h1:rQyoYtj4KddB3bxG6SAqd4+08gePNyJjRqvOIfV3rkM=
154150
github.com/containerd/containerd v1.5.7/go.mod h1:gyvv6+ugqY25TiXxcZC3L5yOeYgEw0QMhscqVp1AR9c=
155151
github.com/containerd/continuity v0.0.0-20190426062206-aaeac12a7ffc/go.mod h1:GL3xCUCBDV3CZiTSEKksMWbLE66hEyuu9qyDOOqM47Y=
@@ -553,8 +549,6 @@ github.com/opencontainers/runc v0.1.1/go.mod h1:qT5XzbpPznkRYVz/mWwUaVBUv2rmF59P
553549
github.com/opencontainers/runc v1.0.0-rc8.0.20190926000215-3e425f80a8c9/go.mod h1:qT5XzbpPznkRYVz/mWwUaVBUv2rmF59PVA73FjuZG0U=
554550
github.com/opencontainers/runc v1.0.0-rc9/go.mod h1:qT5XzbpPznkRYVz/mWwUaVBUv2rmF59PVA73FjuZG0U=
555551
github.com/opencontainers/runc v1.0.0-rc93/go.mod h1:3NOsor4w32B2tC0Zbl8Knk4Wg84SM2ImC1fxBuqJ/H0=
556-
github.com/opencontainers/runc v1.0.1 h1:G18PGckGdAm3yVQRWDVQ1rLSLntiniKJ0cNRT2Tm5gs=
557-
github.com/opencontainers/runc v1.0.1/go.mod h1:aTaHFFwQXuA71CiyxOdFFIorAoemI04suvGRQFzWTD0=
558552
github.com/opencontainers/runc v1.0.2 h1:opHZMaswlyxz1OuGpBE53Dwe4/xF7EZTY0A2L/FpCOg=
559553
github.com/opencontainers/runc v1.0.2/go.mod h1:aTaHFFwQXuA71CiyxOdFFIorAoemI04suvGRQFzWTD0=
560554
github.com/opencontainers/runtime-spec v0.1.2-0.20190507144316-5b71a03e2700/go.mod h1:jwyrGlmzljRJv/Fgzds9SsS/C5hL+LL3ko9hs6T5lQ0=

pkg/api/api.go

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,9 +25,12 @@ func New(token string) *API {
2525
// RequireToken is wrapper around http.HandleFunc that checks token validity
2626
func (api *API) RequireToken(fn http.HandlerFunc) http.HandlerFunc {
2727
return func(w http.ResponseWriter, r *http.Request) {
28-
if r.Header.Get("Authorization") != fmt.Sprintf("Bearer %s", api.Token) {
29-
log.Tracef("Invalid token \"%s\"", r.Header.Get("Authorization"))
30-
log.Tracef("Expected token to be \"%s\"", api.Token)
28+
auth := r.Header.Get("Authorization")
29+
want := fmt.Sprintf("Bearer %s", api.Token)
30+
if auth != want {
31+
log.Tracef("Invalid Authorization header \"%s\"", auth)
32+
log.Tracef("Expected Authorization header to be \"%s\"", want)
33+
w.WriteHeader(http.StatusUnauthorized)
3134
return
3235
}
3336
log.Debug("Valid token found.")

pkg/api/api_test.go

Lines changed: 65 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,65 @@
1+
package api
2+
3+
import (
4+
"io"
5+
"net/http"
6+
"net/http/httptest"
7+
"testing"
8+
9+
. "github.com/onsi/ginkgo"
10+
. "github.com/onsi/gomega"
11+
)
12+
13+
const (
14+
token = "123123123"
15+
)
16+
17+
func TestAPI(t *testing.T) {
18+
RegisterFailHandler(Fail)
19+
RunSpecs(t, "API Suite")
20+
}
21+
22+
var _ = Describe("API", func() {
23+
api := New(token)
24+
25+
Describe("RequireToken middleware", func() {
26+
It("should return 401 Unauthorized when token is not provided", func() {
27+
handlerFunc := api.RequireToken(testHandler)
28+
29+
rec := httptest.NewRecorder()
30+
req := httptest.NewRequest("GET", "/hello", nil)
31+
32+
handlerFunc(rec, req)
33+
34+
Expect(rec.Code).To(Equal(http.StatusUnauthorized))
35+
})
36+
37+
It("should return 401 Unauthorized when token is invalid", func() {
38+
handlerFunc := api.RequireToken(testHandler)
39+
40+
rec := httptest.NewRecorder()
41+
req := httptest.NewRequest("GET", "/hello", nil)
42+
req.Header.Set("Authorization", "Bearer 123")
43+
44+
handlerFunc(rec, req)
45+
46+
Expect(rec.Code).To(Equal(http.StatusUnauthorized))
47+
})
48+
49+
It("should return 200 OK when token is valid", func() {
50+
handlerFunc := api.RequireToken(testHandler)
51+
52+
rec := httptest.NewRecorder()
53+
req := httptest.NewRequest("GET", "/hello", nil)
54+
req.Header.Set("Authorization", "Bearer " + token)
55+
56+
handlerFunc(rec, req)
57+
58+
Expect(rec.Code).To(Equal(http.StatusOK))
59+
})
60+
})
61+
})
62+
63+
func testHandler(w http.ResponseWriter, req *http.Request) {
64+
_, _ = io.WriteString(w, "Hello!")
65+
}

0 commit comments

Comments
 (0)