Repository navigation
Fixes #39767 - Extract account from auth header for all clients - #71
Conversation
3152769 to
e79fb57
Compare
|
@bobbygryzynger Can you describe the workflow with Cincinnati and how it's authenticating against the smart proxy registry. Do you register the host to proxy? Also, does this work for cert-based auth by selecting Deploy container certs in the global registration template? |
Cincinnati is used to fetch container images for updating OpenShift clusters. It uses a Basic Auth header to authenticate against the registry. In Cincinnati:
No registration is performed.
Cincinnati only supports Basic Auth for authentication. It does not support cert-based auth. The proposed change does not affect cert-based auth. Cert-authenticated clients present an RHSM client certificate and do not reach the |
|
@bobbygryzynger Thanks for the context. I will try to test this soon for some clients.. |
|
@bobbygryzynger Can we add a unit test for this? |
89dc225 to
1c5d8df
Compare
|
@sjha4 added test case, ready for you to review. |
The account query parameter is not defined in the CNCF Distribution token authentication spec [1]. The username extraction from the Basic auth header was gated behind flatpak_client?, causing a Sequel::NotNullConstraintViolation for clients like Cincinnati [2] that send valid Basic auth but do not include the non-standard account param. Replace the flatpak_client? guard with a check for a missing account param so the username is extracted from the Basic auth header for any client that omits it. [1] https://distribution.github.io/distribution/spec/auth/token/ [2] https://github.com/openshift/cincinnati Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1c5d8df to
d8f1933
Compare
sjha4
left a comment
There was a problem hiding this comment.
This looks good. I was able to test this against podman, flatpak and skopeo. Do not have Cincinnati setup so I'll rely on your testing to trust that.
Ack 👍🏼
|
Merged..Thanks @bobbygryzynger ! |
The account query parameter is not defined in the CNCF Distribution token authentication spec [1]. The username extraction from the Basic auth header was gated behind flatpak_client?, causing a Sequel::NotNullConstraintViolation for clients like Cincinnati [2] that send valid Basic auth but do not include the non-standard account param. Replace the flatpak_client? guard with a check for a missing account param so the username is extracted from the Basic auth header for any client that omits it.
[1] https://distribution.github.io/distribution/spec/auth/token/
[2] https://github.com/openshift/cincinnati