🐛(backend) use the configured token type in BaseJWTAuthentication

authenticate and authenticate_header hardcoded "Bearer" instead of
using the token type the backend is configured with. Setting
APPLICATION_JWT_TOKEN_TYPE, ADDONS_TOKEN_TYPE or USER_ACCESS_TOKEN_TYPE
to anything else made every token be ignored, since the Authorization
scheme never matched.

Store the token type on the backend and use it both to match the
Authorization header scheme (case-insensitively) and as the
WWW-Authenticate scheme.
This commit is contained in:
lebaudantoine
2026-10-08 18:27:02 +02:00
parent 6d87c2665d
commit fc905c654d
@@ -48,6 +48,7 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
self.is_enabled = is_enabled
self._token_service = None
self._token_type = token_type
if not self.is_enabled:
return
@@ -73,7 +74,10 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
auth_header = authentication.get_authorization_header(request).split()
if not auth_header or auth_header[0].lower() != b"bearer":
if (
not auth_header
or auth_header[0].lower() != self._token_type.lower().encode()
):
# Defer to next authentication backend
return None
@@ -159,7 +163,7 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
def authenticate_header(self, request):
"""Return authentication scheme for WWW-Authenticate header."""
return "Bearer"
return self._token_type
def authenticate_credentials(self, token):
"""Validate JWT token and return authenticated user.