Skip to content

Fixes #39767 - Extract account from auth header for all clients - #71

Merged
sjha4 merged 1 commit into
Katello:mainfrom
bobbygryzynger:extract-account-from-auth-header-for-all-clients
Sep 17, 2026
Merged

sjha4 merged 1 commit into
Katello:mainfrom
bobbygryzynger:extract-account-from-auth-header-for-all-clients

Conversation

@bobbygryzynger

Copy link
Copy Markdown
Contributor

The account query parameter is not defined in the CNCF Distribution token authentication spec [1]. The username extraction from the Basic auth header was gated behind flatpak_client?, causing a Sequel::NotNullConstraintViolation for clients like Cincinnati [2] that send valid Basic auth but do not include the non-standard account param. Replace the flatpak_client? guard with a check for a missing account param so the username is extracted from the Basic auth header for any client that omits it.

[1] https://distribution.github.io/distribution/spec/auth/token/
[2] https://github.com/openshift/cincinnati

@sjha4

sjha4 commented Sep 9, 2026

Copy link
Copy Markdown
Member

@bobbygryzynger Can you describe the workflow with Cincinnati and how it's authenticating against the smart proxy registry. Do you register the host to proxy? Also, does this work for cert-based auth by selecting Deploy container certs in the global registration template?

@bobbygryzynger

bobbygryzynger commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor Author

@sjha4

Can you describe the workflow with Cincinnati and how it's authenticating against the smart proxy registry.

Cincinnati is used to fetch container images for updating OpenShift clusters. It uses a Basic Auth header to authenticate against the registry.

In Cincinnati:

  1. Username/password is used when creating a registry client: https://github.com/openshift/cincinnati/blob/6a281003aa314383cae326fb218447cff0697fb5/cincinnati/src/plugins/internal/graph_builder/release_scrape_dockerv2/registry/mod.rs#L202-L250
  2. WWW-Authenticate header is parsed (using dkregistry-rs dependency): https://github.com/camallo/dkregistry-rs/blob/8e021d03859541c0f58f86f1f65aa986c6809222/src/v2/auth.rs#L244-L283
  3. Request is made using Basic Auth header (using dkregistry-rs dependency): https://github.com/camallo/dkregistry-rs/blob/8e021d03859541c0f58f86f1f65aa986c6809222/src/v2/auth.rs#L34-L58

Do you register the host to proxy?

No registration is performed.

Also, does this work for cert-based auth by selecting Deploy container certs in the global registration template?

Cincinnati only supports Basic Auth for authentication. It does not support cert-based auth. The proposed change does not affect cert-based auth. Cert-authenticated clients present an RHSM client certificate and do not reach the /v2/token endpoint where this change applies.

@sjha4

sjha4 commented Sep 9, 2026

Copy link
Copy Markdown
Member

@bobbygryzynger Thanks for the context. I will try to test this soon for some clients..

@sjha4

sjha4 commented Sep 15, 2026

Copy link
Copy Markdown
Member

@bobbygryzynger Can we add a unit test for this?

@bobbygryzynger
bobbygryzynger force-pushed the extract-account-from-auth-header-for-all-clients branch from 89dc225 to 1c5d8df Compare September 15, 2026 18:01
@bobbygryzynger bobbygryzynger changed the title Fixes #70 - Extract account from auth header for all clients Fixes #39767 - Extract account from auth header for all clients Sep 15, 2026
@bobbygryzynger

Copy link
Copy Markdown
Contributor Author

@sjha4 added test case, ready for you to review.

The account query parameter is not defined in the CNCF Distribution
token authentication spec [1]. The username extraction from the
Basic auth header was gated behind flatpak_client?, causing a
Sequel::NotNullConstraintViolation for clients like Cincinnati [2]
that send valid Basic auth but do not include the non-standard
account param. Replace the flatpak_client? guard with a check for
a missing account param so the username is extracted from the Basic
auth header for any client that omits it.

[1] https://distribution.github.io/distribution/spec/auth/token/
[2] https://github.com/openshift/cincinnati

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@bobbygryzynger
bobbygryzynger force-pushed the extract-account-from-auth-header-for-all-clients branch from 1c5d8df to d8f1933 Compare September 15, 2026 21:39

@sjha4 sjha4 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good. I was able to test this against podman, flatpak and skopeo. Do not have Cincinnati setup so I'll rely on your testing to trust that.

Ack 👍🏼

@sjha4
sjha4 merged commit f470a39 into Katello:main Sep 17, 2026
11 checks passed
@sjha4

sjha4 commented Sep 17, 2026

Copy link
Copy Markdown
Member

Merged..Thanks @bobbygryzynger !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants