|
Bearer auth fails closed: a dead token no longer rides the session cookie
Presenting an invalid or revoked token used to fall through to the session cookie in the same request, silently authenticating as channel=ui with the session's privileges — a revoked token kept "working" inside a logged-in browser and masked revocation (and the extension with it). Now a Bearer header is final: a token that does not authenticate answers 401; cookie auth is only for requests without one. Regression test added. Co-Authored-By: Claude Code <noreply@anthropic.com> |
|---|
|
|
| gnexus_creds/auth.py |
|---|
| tests/test_auth.py |
|---|