forgejo-mcp/pkg/forgejo
Christoph Görn 63e16242a3
fix: 🔒️ reject bare tokens in stateless HTTP auth
extractToken accepted Authorization values with no scheme prefix,
silently treating them as per-request tokens. The stateless-http-auth
spec mandates bare tokens be rejected and treated as no header. Drop
the fallback branch so unrecognized/scheme-less values fall through to
the global singleton instead of forging an identity.

- operation: extractToken returns "" for scheme-less headers (task 2.5)
- test: extractToken case-insensitivity + bare-token rejection (4.4)
- test: ephemeral-client construction failure surfaces error, no
  singleton downgrade (4.3)
- docs: cross-link stateless-http-auth OpenSpec change from README (5.2)
- tasks: mark completed blocker fixes (1.3, 2.4, 2.5, 4.2-4.4, 5.x, 6.3)
2026-06-01 23:41:10 +02:00
..
forgejo.go feat: robust stateless auth with security fixes and improved tests 2026-05-24 13:44:48 +02:00
forgejo_test.go fix: 🔒️ reject bare tokens in stateless HTTP auth 2026-06-01 23:41:10 +02:00
rawhttp.go merge: resolve conflicts with upstream/main 2026-05-24 14:18:59 +02:00
rawhttp_test.go style: 🎨 apply gofmt -w to operation/* and pkg/* 2026-05-24 09:24:48 +02:00
testing.go deps: ⬆️ migrate forgejo-sdk from v2 to v3 2026-03-27 23:53:31 +01:00