Bearer auth fails closed: a dead token no longer rides the session cookie
Presenting an invalid or revoked token used to fall through to the
session cookie in the same request, silently authenticating as
channel=ui with the session's privileges — a revoked token kept
"working" inside a logged-in browser and masked revocation (and the
extension with it). Now a Bearer header is final: a token that does not
authenticate answers 401; cookie auth is only for requests without one.
Regression test added.

Co-Authored-By: Claude Code <noreply@anthropic.com>
1 parent 287b7a0 commit 53acfb41bb8f274d9d9443ddfd2ab8607533d37f
@Eugene Sukhodolskiy Eugene Sukhodolskiy authored 1 hour ago
Showing 2 changed files
View
gnexus_creds/auth.py
View
tests/test_auth.py