User Story
As a developer integrating a third-party gRPC/HTTP client or SDK with an OpenShell gateway,
I want standards-compliant Authorization headers to be accepted regardless of scheme casing,
so that my client authenticates without OpenShell-specific header workarounds.
Problem Statement
Every bearer-token extraction site uses strip_prefix("Bearer "), so the auth scheme is matched case-sensitively and with exactly one space. RFC 7235 §2.1 and RFC 6750 define the scheme name as case-insensitive, so authorization: bearer <token> or BEARER <token> is a valid header that OpenShell rejects as unauthenticated.
Sites on main (0ea0d31):
|
.and_then(|v| v.strip_prefix("Bearer ")) |
|
.and_then(|v| v.strip_prefix("Bearer ")) |
|
.and_then(|value| value.strip_prefix("Bearer ")) |
|
.and_then(|value| value.strip_prefix("Bearer ")) |
|
.and_then(|value| value.strip_prefix("Bearer ")) |
-
openshell-core/src/jwt.rs#L21 and grpc_client.rs#L668 fall back to treating the whole value as the token, so bearer xyz becomes the token bearer xyz.
Impact / Why This Matters
Clients and proxies that normalize or lower-case the scheme (some HTTP libraries, API gateways, service meshes, hand-written SDKs) get UNAUTHENTICATED with no hint that casing is the cause. Users have to debug the gateway to find out that only Bearer with exact casing works. The behavior is also inconsistent across entry points: some sites reject the header, while others pass a malformed token downstream.
Acceptance Criteria
Reproduction Steps
- Start a local gateway with OIDC (or use a sandbox session JWT).
- Call any authenticated RPC with
grpcurl -H 'authorization: bearer <valid-token>' ....
- Observe
Unauthenticated; the same call with Bearer succeeds.
Environment
- OpenShell:
main @ 0ea0d31 (code review)
- Components:
openshell-server auth, openshell-sandbox-backend, openshell-core
Logs
User Story
As a developer integrating a third-party gRPC/HTTP client or SDK with an OpenShell gateway,
I want standards-compliant
Authorizationheaders to be accepted regardless of scheme casing,so that my client authenticates without OpenShell-specific header workarounds.
Problem Statement
Every bearer-token extraction site uses
strip_prefix("Bearer "), so the auth scheme is matched case-sensitively and with exactly one space. RFC 7235 §2.1 and RFC 6750 define the scheme name as case-insensitive, soauthorization: bearer <token>orBEARER <token>is a valid header that OpenShell rejects as unauthenticated.Sites on
main(0ea0d31):OpenShell/crates/openshell-server/src/auth/oidc.rs
Line 897 in 0ea0d31
OpenShell/crates/openshell-server/src/auth/peer.rs
Line 99 in 0ea0d31
OpenShell/crates/openshell-server/src/auth/sandbox_jwt.rs
Line 282 in 0ea0d31
OpenShell/crates/openshell-server/src/auth/compute_driver.rs
Line 40 in 0ea0d31
OpenShell/crates/openshell-server/src/grpc/auth_rpc.rs
Line 203 in 0ea0d31
OpenShell/crates/openshell-sandbox-backend/src/sandbox_auth.rs
Line 107 in 0ea0d31
openshell-core/src/jwt.rs#L21andgrpc_client.rs#L668fall back to treating the whole value as the token, sobearer xyzbecomes the tokenbearer xyz.Impact / Why This Matters
Clients and proxies that normalize or lower-case the scheme (some HTTP libraries, API gateways, service meshes, hand-written SDKs) get
UNAUTHENTICATEDwith no hint that casing is the cause. Users have to debug the gateway to find out that onlyBearerwith exact casing works. The behavior is also inconsistent across entry points: some sites reject the header, while others pass a malformed token downstream.Acceptance Criteria
bearer <t>,Bearer <t>andBEARER <t>authenticate identically; empty or whitespace-containing tokens are still rejected.Reproduction Steps
grpcurl -H 'authorization: bearer <valid-token>' ....Unauthenticated; the same call withBearersucceeds.Environment
main@ 0ea0d31 (code review)openshell-serverauth,openshell-sandbox-backend,openshell-coreLogs