Skip to content

[BUG] Authorization header erroneously stripped during request handling #1130

@chuckwondo

Description

@chuckwondo

Is this issue already tracked somewhere, or is this a new report?

  • I've reviewed existing issues and couldn't find a duplicate for this problem.

Current Behavior

This is a follow-on from #864. Because we have a hard-coded list of "allowed" hosts, when a valid host is not in the allow list, a valid Authorization header will be erroneously stripped, causing auth failure.

For a potential solution, see #864 (comment)

Expected Behavior

The Authorization header is not stripped.

Steps To Reproduce

See #864

Environment

- OS: all
- Python: all

Additional Context

No response

Metadata

Metadata

Assignees

Labels

type: bugSomething isn't working

Type

No type

Projects

Status

🆕 New

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions