debug: add logging for OIDC token validation
🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.5
parent
6243f29aae
commit
ce761a9d2c
@@ -190,8 +190,9 @@ async def get_current_user(
|
|||||||
raise HTTPException(status_code=401, detail="Invalid token format")
|
raise HTTPException(status_code=401, detail="Invalid token format")
|
||||||
|
|
||||||
# Validate issuer is in allowed list
|
# Validate issuer is in allowed list
|
||||||
|
logger.debug(f"Token issuer: {token_issuer}, allowed issuers: {oidc_config.issuers}")
|
||||||
if not oidc_config.is_valid_issuer(token_issuer):
|
if not oidc_config.is_valid_issuer(token_issuer):
|
||||||
logger.warning(f"Invalid token issuer: {token_issuer}")
|
logger.warning(f"Invalid token issuer: {token_issuer} (allowed: {oidc_config.issuers})")
|
||||||
raise HTTPException(status_code=401, detail="Invalid token issuer")
|
raise HTTPException(status_code=401, detail="Invalid token issuer")
|
||||||
|
|
||||||
# Get JWKS for this specific issuer
|
# Get JWKS for this specific issuer
|
||||||
@@ -315,12 +316,14 @@ async def get_optional_user(
|
|||||||
}
|
}
|
||||||
|
|
||||||
if not credentials:
|
if not credentials:
|
||||||
|
logger.debug("No credentials provided for optional auth")
|
||||||
return None
|
return None
|
||||||
|
|
||||||
try:
|
try:
|
||||||
return await get_current_user(credentials)
|
return await get_current_user(credentials)
|
||||||
except HTTPException:
|
except HTTPException as e:
|
||||||
# Invalid token - return None instead of raising
|
# Invalid token - log and return None instead of raising
|
||||||
|
logger.warning(f"Optional auth failed: {e.detail}")
|
||||||
return None
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user