Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve error message for invalid JWT Header values (backport #7121) #7127

Merged
merged 1 commit into from
Mar 28, 2025

Conversation

IvanGoncharov
Copy link
Member

Enhanced parsing error messages for JWT Authorization header values now provide developers with clear, actionable feedback while ensuring that no sensitive data is exposed.

Examples of the updated error messages:

-         Header Value: '<invalid value>' is not correctly formatted. prefix should be 'Bearer'
+         Value of 'authorization' JWT header should be prefixed with 'Bearer'
-         Header Value: 'Bearer' is not correctly formatted. Missing JWT
+         Value of 'authorization' JWT header has only 'Bearer' prefix but no JWT token

Fixes #issue_number


Checklist

Complete the checklist (and note appropriate exceptions) before the PR is marked ready-for-review.

  • Changes are compatible1
  • Documentation2 completed
  • Performance impact assessed and acceptable
  • Tests added and passing3
    • Unit Tests
    • Integration Tests
    • Manual Tests

Exceptions

Note any exceptions here

Notes

[ROUTER-1212]: https://apollographql.atlassian.net/browse/ROUTER-1212?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ


This is an automatic backport of pull request #7121 done by Mergify.

Footnotes

  1. It may be appropriate to bring upcoming changes to the attention of other (impacted) groups. Please endeavour to do this before seeking PR approval. The mechanism for doing this will vary considerably, so use your judgement as to how and when to do this.

  2. Configuration is an important part of many changes. Where applicable please try to document configuration examples.

  3. Tick whichever testing boxes are applicable. If you are adding Manual Tests, please document the manual testing (extensively) in the Exceptions.

@IvanGoncharov IvanGoncharov requested a review from a team as a code owner March 26, 2025 16:46
@mergify mergify bot added the conflicts label Mar 26, 2025
@IvanGoncharov IvanGoncharov requested review from a team as code owners March 26, 2025 16:46
Copy link
Contributor

mergify bot commented Mar 26, 2025

Cherry-pick of 65c20a8 has failed:

On branch mergify/bp/1.x/pr-7121
Your branch is up to date with 'origin/1.x'.

You are currently cherry-picking commit 65c20a8b.
  (fix conflicts and run "git cherry-pick --continue")
  (use "git cherry-pick --skip" to skip this patch)
  (use "git cherry-pick --abort" to cancel the cherry-pick operation)

Changes to be committed:
	new file:   .changesets/fix_improve_jwt_errors.md
	modified:   apollo-router/src/plugins/authentication/tests.rs

Unmerged paths:
  (use "git add/rm <file>..." as appropriate to mark resolution)
	deleted by us:   apollo-router/src/plugins/authentication/error.rs
	both modified:   apollo-router/src/plugins/authentication/jwks.rs

To fix up this pull request, you can check it out locally. See documentation: https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/reviewing-changes-in-pull-requests/checking-out-pull-requests-locally

@svc-apollo-docs
Copy link
Collaborator

svc-apollo-docs commented Mar 26, 2025

✅ Docs preview has no changes

The preview was not built because there were no changes.

Build ID: 29bde918b04bbb1a71d1efd8

@IvanGoncharov IvanGoncharov force-pushed the mergify/bp/1.x/pr-7121 branch from fedf5be to 420cadc Compare March 26, 2025 16:51
@IvanGoncharov IvanGoncharov merged commit a2a0c3b into 1.x Mar 28, 2025
14 checks passed
@IvanGoncharov IvanGoncharov deleted the mergify/bp/1.x/pr-7121 branch March 28, 2025 12:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants