Skip to content

Commit b4189c2

Browse files
locker95thaJeztah
authored andcommitted
registry: map login HTTP status through errhttp.ToNative
translateV2AuthError only unwraps a url.Error from Do(); a 401 status never went through it. Use errhttp.ToNative so Auth() treats that 401 as unauthorized and stops. Signed-off-by: Dean Chen <862469039@qq.com> Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
1 parent 5e0fdb3 commit b4189c2

3 files changed

Lines changed: 4 additions & 6 deletions

File tree

‎internal/registry/auth.go‎

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ import (
88
"strings"
99
"time"
1010

11+
"github.com/containerd/errdefs/pkg/errhttp"
1112
"github.com/containerd/log"
1213
"github.com/docker/distribution/registry/client/auth"
1314
"github.com/docker/distribution/registry/client/auth/challenge"
@@ -67,11 +68,7 @@ func loginV2(ctx context.Context, authConfig *registry.AuthConfig, endpoint APIE
6768

6869
if resp.StatusCode != http.StatusOK {
6970
// TODO(dmcgowan): Attempt to further interpret result, status code and error code string
70-
err := fmt.Errorf("login attempt to %s failed with status: %d %s", endpointStr, resp.StatusCode, http.StatusText(resp.StatusCode))
71-
if resp.StatusCode == http.StatusUnauthorized {
72-
return "", unauthorizedErr{err}
73-
}
74-
return "", err
71+
return "", fmt.Errorf("login attempt to %s failed with status: %d %s: %w", endpointStr, resp.StatusCode, http.StatusText(resp.StatusCode), errhttp.ToNative(resp.StatusCode))
7572
}
7673

7774
return credentialAuthConfig.IdentityToken, nil

‎internal/registry/auth_test.go‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,7 @@ func TestLoginV2BasicAuthUnauthorized(t *testing.T) {
3333
_, err = loginV2(ctx, &registry.AuthConfig{Username: "alice", Password: "wrong"}, endpoint, "docker-test")
3434
assert.ErrorContains(t, err, "401")
3535
assert.Check(t, errdefs.IsUnauthorized(err))
36+
assert.Check(t, is.ErrorType(err, errdefs.IsUnauthorized))
3637

3738
token, err := loginV2(ctx, &registry.AuthConfig{Username: "alice", Password: "secret"}, endpoint, "docker-test")
3839
assert.NilError(t, err)

‎vendor.mod‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@ tool (
1414
require (
1515
dario.cat/mergo v1.0.2
1616
github.com/containerd/errdefs v1.0.0
17+
github.com/containerd/errdefs/pkg v0.3.0
1718
github.com/containerd/log v0.1.0
1819
github.com/containerd/platforms v1.0.0-rc.5
1920
github.com/creack/pty v1.1.24
@@ -75,7 +76,6 @@ require (
7576
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
7677
github.com/cespare/xxhash/v2 v2.3.0 // indirect
7778
github.com/clipperhouse/uax29/v2 v2.2.0 // indirect
78-
github.com/containerd/errdefs/pkg v0.3.0 // indirect
7979
github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect
8080
github.com/docker/go-events v0.0.0-20260608200158-dbf6103125a4 // indirect
8181
github.com/docker/go-metrics v0.1.0 // indirect

0 commit comments

Comments
 (0)