Skip to content

Conversation

@deve-sh
Copy link
Collaborator

@deve-sh deve-sh commented Sep 5, 2025

Works to fix postmanlabs/postman-app-support#13756

Context

Since servers can return multiple values for www-authenticate headers to present clients with multiple options, we need to filter the right header based on the auth.algorithm setting passed by postman-runtime's consumer.

@codecov
Copy link

codecov bot commented Sep 5, 2025

Codecov Report

❌ Patch coverage is 41.66667% with 7 lines in your changes missing coverage. Please review.
✅ Project coverage is 38.62%. Comparing base (92efc97) to head (439e2e2).
⚠️ Report is 1 commits behind head on develop.

Files with missing lines Patch % Lines
lib/authorizer/digest.js 41.66% 6 Missing and 1 partial ⚠️

❌ Your patch status has failed because the patch coverage (41.66%) is below the target coverage (100.00%). You can increase the patch coverage or adjust the target coverage.

Additional details and impacted files
@@             Coverage Diff             @@
##           develop    #1524      +/-   ##
===========================================
- Coverage    38.66%   38.62%   -0.05%     
===========================================
  Files           46       46              
  Lines         3525     3534       +9     
  Branches      1023     1026       +3     
===========================================
+ Hits          1363     1365       +2     
- Misses        2065     2071       +6     
- Partials        97       98       +1     
Flag Coverage Δ
unit 38.62% <41.66%> (-0.05%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link
Member

@appurva21 appurva21 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Logic looks good. Suggested some optional refactoring.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we add tests for this?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I checked the digest auth server we run for our integration suite, that version of passport doesn't seem to support multiple digest auth headers as part of www-authenticate.

I'll check a little further and find another way to verify this change.

appurva21
appurva21 previously approved these changes Sep 8, 2025
Copy link
Member

@appurva21 appurva21 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Tests to be added.

@appurva21 appurva21 merged commit 741a19a into develop Sep 8, 2025
9 of 14 checks passed
@appurva21 appurva21 deleted the fix/multiple-digest-authentication-headers-not-filtered-by-opted-algorithm branch September 8, 2025 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: Digest Auth uses incorrect nonce when multiple WWW-Authenticate headers are present

2 participants