extractToken accepted Authorization values with no scheme prefix, silently treating them as per-request tokens. The stateless-http-auth spec mandates bare tokens be rejected and treated as no header. Drop the fallback branch so unrecognized/scheme-less values fall through to the global singleton instead of forging an identity. - operation: extractToken returns "" for scheme-less headers (task 2.5) - test: extractToken case-insensitivity + bare-token rejection (4.4) - test: ephemeral-client construction failure surfaces error, no singleton downgrade (4.3) - docs: cross-link stateless-http-auth OpenSpec change from README (5.2) - tasks: mark completed blocker fixes (1.3, 2.4, 2.5, 4.2-4.4, 5.x, 6.3) |
||
|---|---|---|
| .. | ||
| diff | ||
| flag | ||
| forgejo | ||
| log | ||
| ptr | ||
| to | ||