Add test for parsing bearer tokens.

This commit is contained in:
Juliusz Chroboczek
2023-12-09 20:46:45 +01:00
parent f9ef43248b
commit 5c2e5ee5c0
2 changed files with 33 additions and 4 deletions
+4 -4
View File
@@ -52,8 +52,7 @@ func canPresent(perms []string) bool {
return false
}
func getBearerToken(r *http.Request) string {
auth := r.Header.Get("Authorization")
func parseBearerToken(auth string) string {
auths := strings.Split(auth, ",")
for _, a := range auths {
a = strings.Trim(a, " \t")
@@ -178,7 +177,8 @@ func whipEndpointHandler(w http.ResponseWriter, r *http.Request) {
return
}
token := getBearerToken(r)
token := parseBearerToken(r.Header.Get("Authorization"))
whip := "whip"
creds := group.ClientCredentials{
Username: &whip,
@@ -258,7 +258,7 @@ func whipResourceHandler(w http.ResponseWriter, r *http.Request) {
}
if t := c.Token(); t != "" {
token := getBearerToken(r)
token := parseBearerToken(r.Header.Get("Authorization"))
if token != t {
http.Error(w, "Forbidden", http.StatusForbidden)
return