extractToken accepted Authorization values with no scheme prefix, silently treating them as per-request tokens. The stateless-http-auth spec mandates bare tokens be rejected and treated as no header. Drop the fallback branch so unrecognized/scheme-less values fall through to the global singleton instead of forging an identity. - operation: extractToken returns "" for scheme-less headers (task 2.5) - test: extractToken case-insensitivity + bare-token rejection (4.4) - test: ephemeral-client construction failure surfaces error, no singleton downgrade (4.3) - docs: cross-link stateless-http-auth OpenSpec change from README (5.2) - tasks: mark completed blocker fixes (1.3, 2.4, 2.5, 4.2-4.4, 5.x, 6.3) |
||
|---|---|---|
| .. | ||
| forgejo.go | ||
| forgejo_test.go | ||
| rawhttp.go | ||
| rawhttp_test.go | ||
| testing.go | ||