yasithdev opened a new pull request, #642: URL: https://github.com/apache/airavata/pull/642
GrpcAuthInterceptor and HttpAuthDecorator each independently stripped the Bearer prefix from the authorization header, parsed the x-claims JSON header (each with its own ObjectMapper), and built the AuthzToken — so a change to that parsing had to be made in two places. A new AuthTokenExtractor in the same package provides the three shared steps (stripBearer, parseClaims, buildAuthzToken) behind one ObjectMapper. Each transport keeps its own concerns: the gRPC interceptor's UNAUTHENTICATED close, the HTTP decorator's UNAUTHORIZED return and per-header (x-user-name / x-gateway-id) claims fallback, and each path's UserContext lifecycle. Behavior-preserving and the full reactor builds green. (The only airavata-server unit-test failures are in the unrelated FileControllerTest, which fails identically on master.) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
