yasithdev opened a new pull request, #642:
URL: https://github.com/apache/airavata/pull/642

   GrpcAuthInterceptor and HttpAuthDecorator each independently stripped the 
Bearer prefix from the authorization header, parsed the x-claims JSON header 
(each with its own ObjectMapper), and built the AuthzToken — so a change to 
that parsing had to be made in two places. A new AuthTokenExtractor in the same 
package provides the three shared steps (stripBearer, parseClaims, 
buildAuthzToken) behind one ObjectMapper. Each transport keeps its own 
concerns: the gRPC interceptor's UNAUTHENTICATED close, the HTTP decorator's 
UNAUTHORIZED return and per-header (x-user-name / x-gateway-id) claims 
fallback, and each path's UserContext lifecycle. Behavior-preserving and the 
full reactor builds green. (The only airavata-server unit-test failures are in 
the unrelated FileControllerTest, which fails identically on master.)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to