Skip to content

bug(auth): Authorization header parsing requires exact-case Bearer and rejects valid bearer scheme #3903

Description

@CloneOfAlex

User Story

As a developer integrating a third-party gRPC/HTTP client or SDK with an OpenShell gateway,
I want standards-compliant Authorization headers to be accepted regardless of scheme casing,
so that my client authenticates without OpenShell-specific header workarounds.

Problem Statement

Every bearer-token extraction site uses strip_prefix("Bearer "), so the auth scheme is matched case-sensitively and with exactly one space. RFC 7235 §2.1 and RFC 6750 define the scheme name as case-insensitive, so authorization: bearer <token> or BEARER <token> is a valid header that OpenShell rejects as unauthenticated.

Sites on main (0ea0d31):

Impact / Why This Matters

Clients and proxies that normalize or lower-case the scheme (some HTTP libraries, API gateways, service meshes, hand-written SDKs) get UNAUTHENTICATED with no hint that casing is the cause. Users have to debug the gateway to find out that only Bearer with exact casing works. The behavior is also inconsistent across entry points: some sites reject the header, while others pass a malformed token downstream.

Acceptance Criteria

  • The scheme comparison is ASCII case-insensitive at all listed sites (ideally one shared helper).
  • bearer <t>, Bearer <t> and BEARER <t> authenticate identically; empty or whitespace-containing tokens are still rejected.
  • Unit tests cover the case variants for the OIDC, sandbox JWT, and sandbox protocol authenticators.

Reproduction Steps

  1. Start a local gateway with OIDC (or use a sandbox session JWT).
  2. Call any authenticated RPC with grpcurl -H 'authorization: bearer <valid-token>' ....
  3. Observe Unauthenticated; the same call with Bearer succeeds.

Environment

  • OpenShell: main @ 0ea0d31 (code review)
  • Components: openshell-server auth, openshell-sandbox-backend, openshell-core

Logs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions