forgejo-mcp/pkg
Christoph Görn 63e16242a3
fix: 🔒️ reject bare tokens in stateless HTTP auth
extractToken accepted Authorization values with no scheme prefix,
silently treating them as per-request tokens. The stateless-http-auth
spec mandates bare tokens be rejected and treated as no header. Drop
the fallback branch so unrecognized/scheme-less values fall through to
the global singleton instead of forging an identity.

- operation: extractToken returns "" for scheme-less headers (task 2.5)
- test: extractToken case-insensitivity + bare-token rejection (4.4)
- test: ephemeral-client construction failure surfaces error, no
  singleton downgrade (4.3)
- docs: cross-link stateless-http-auth OpenSpec change from README (5.2)
- tasks: mark completed blocker fixes (1.3, 2.4, 2.5, 4.2-4.4, 5.x, 6.3)
2026-06-01 23:41:10 +02:00
..
diff feat: bounded responses for get_pull_request_diff + get_file_content (#131) 2026-05-12 10:41:52 +02:00
flag feat: ✨ add streamable HTTP transport support (#99) 2026-03-28 00:07:10 +01:00
forgejo fix: 🔒️ reject bare tokens in stateless HTTP auth 2026-06-01 23:41:10 +02:00
log fix: add /v2 suffix to module path for go install compatibility 2025-12-29 15:51:03 +01:00
ptr Add k8s ptr 2025-03-23 14:53:03 +08:00
to feat: ✨ add issue/PR time tracking and stopwatch tools 2026-04-21 22:49:07 +02:00