From 6702f07a872ba2ee1925219ba83ad63d76da6103 Mon Sep 17 00:00:00 2001 From: Misi Date: Fri, 26 May 2023 10:22:59 +0200 Subject: [PATCH] AuthN: Use EqualFold for skipping introspection endpoint (#69126) Add equality check for introspect ep in basic.go --- pkg/services/authn/clients/basic.go | 2 +- pkg/services/authn/clients/basic_test.go | 6 ++++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/pkg/services/authn/clients/basic.go b/pkg/services/authn/clients/basic.go index 4d93abd5449..cca31b6458d 100644 --- a/pkg/services/authn/clients/basic.go +++ b/pkg/services/authn/clients/basic.go @@ -44,7 +44,7 @@ func (c *Basic) Test(ctx context.Context, r *authn.Request) bool { return false } // The OAuth2 introspection endpoint uses basic auth but is handled by the oauthserver package. - if strings.HasPrefix(r.HTTPRequest.RequestURI, "/oauth2/introspect") { + if strings.EqualFold(r.HTTPRequest.RequestURI, "/oauth2/introspect") { return false } return looksLikeBasicAuthRequest(r) diff --git a/pkg/services/authn/clients/basic_test.go b/pkg/services/authn/clients/basic_test.go index fbf2a96a2d7..93fbd7d4165 100644 --- a/pkg/services/authn/clients/basic_test.go +++ b/pkg/services/authn/clients/basic_test.go @@ -85,6 +85,12 @@ func TestBasic_Test(t *testing.T) { HTTPRequest: &http.Request{Header: map[string][]string{authorizationHeaderName: {"something"}}}, }, }, + { + desc: "should fail when the URL ends with /oauth2/introspect", + req: &authn.Request{ + HTTPRequest: &http.Request{Header: map[string][]string{authorizationHeaderName: {encodeBasicAuth("user", "password")}}, RequestURI: "/oauth2/introspect"}, + }, + }, } for _, tt := range tests {