fix(api): a session-store outage answers 503, not 401
Resolving a session cookie failed identically whether the credential was missing or Postgres was unreachable: local_auth_enabled read errors fell into the fail-closed 'disabled' branch and SessionUser errors into 'invalid session', both surfacing as 401 'authentication required' — a lie that reads as 'log in again' during an outage. Split the enabled-read into (enabled, error), tag non-ErrNotFound store failures with errAuthBackend, and map that to a new 503 auth_unavailable in requireExternal. Fail-closed is unchanged: missing setting / bad value / missing session stay 401.
This commit is contained in:
4 files changed
+93
-8
No files matched your search
@@ -4,6 +4,7 @@ import (
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"encoding/hex"
|
||||
"errors"
|
||||
"log"
|
||||
"net/http"
|
||||
"runtime/debug"
|
||||
@@ -95,6 +96,11 @@ func (a *API) requireInternal(next http.Handler) http.Handler {
|
||||
func (a *API) requireExternal(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
p, err := a.External.Authenticate(r)
|
||||
if errors.Is(err, errAuthBackend) {
|
||||
// Session store unreachable — an outage, not a missing credential.
|
||||
writeError(w, r, errAuthUnavailable)
|
||||
return
|
||||
}
|
||||
if err != nil || p == nil {
|
||||
writeError(w, r, errUnauthorized)
|
||||
return
|
||||
|
||||
Reference in new issue
Block a user