From fc905c654dbf4a00849481fe5e447dcecee866f1 Mon Sep 17 00:00:00 2001 From: lebaudantoine Date: Thu, 8 Oct 2026 18:27:02 +0200 Subject: [PATCH] =?UTF-8?q?=F0=9F=90=9B(backend)=20use=20the=20configured?= =?UTF-8?q?=20token=20type=20in=20BaseJWTAuthentication?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit authenticate and authenticate_header hardcoded "Bearer" instead of using the token type the backend is configured with. Setting APPLICATION_JWT_TOKEN_TYPE, ADDONS_TOKEN_TYPE or USER_ACCESS_TOKEN_TYPE to anything else made every token be ignored, since the Authorization scheme never matched. Store the token type on the backend and use it both to match the Authorization header scheme (case-insensitively) and as the WWW-Authenticate scheme. --- src/backend/core/external_api/authentication.py | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/src/backend/core/external_api/authentication.py b/src/backend/core/external_api/authentication.py index 445eb02f4..07dfeb1c1 100644 --- a/src/backend/core/external_api/authentication.py +++ b/src/backend/core/external_api/authentication.py @@ -48,6 +48,7 @@ class BaseJWTAuthentication(authentication.BaseAuthentication): self.is_enabled = is_enabled self._token_service = None + self._token_type = token_type if not self.is_enabled: return @@ -73,7 +74,10 @@ class BaseJWTAuthentication(authentication.BaseAuthentication): auth_header = authentication.get_authorization_header(request).split() - if not auth_header or auth_header[0].lower() != b"bearer": + if ( + not auth_header + or auth_header[0].lower() != self._token_type.lower().encode() + ): # Defer to next authentication backend return None @@ -159,7 +163,7 @@ class BaseJWTAuthentication(authentication.BaseAuthentication): def authenticate_header(self, request): """Return authentication scheme for WWW-Authenticate header.""" - return "Bearer" + return self._token_type def authenticate_credentials(self, token): """Validate JWT token and return authenticated user.