fix(api): a session-store outage answers 503, not 401

Resolving a session cookie failed identically whether the credential was
missing or Postgres was unreachable: local_auth_enabled read errors fell into
the fail-closed 'disabled' branch and SessionUser errors into 'invalid
session', both surfacing as 401 'authentication required' — a lie that reads
as 'log in again' during an outage. Split the enabled-read into
(enabled, error), tag non-ErrNotFound store failures with errAuthBackend, and
map that to a new 503 auth_unavailable in requireExternal. Fail-closed is
unchanged: missing setting / bad value / missing session stay 401.
This commit is contained in:
Lemon-miaow committed 2026-09-22 20:30:43 +08:00
1 parent abce381faa
commit 2a8f897e61
4 files changed
+93 -8

No files matched your search

+6
View File
@@ -4,6 +4,7 @@ import (
"context"
"crypto/rand"
"encoding/hex"
"errors"
"log"
"net/http"
"runtime/debug"
@@ -95,6 +96,11 @@ func (a *API) requireInternal(next http.Handler) http.Handler {
func (a *API) requireExternal(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
p, err := a.External.Authenticate(r)
if errors.Is(err, errAuthBackend) {
// Session store unreachable — an outage, not a missing credential.
writeError(w, r, errAuthUnavailable)
return
}
if err != nil || p == nil {
writeError(w, r, errUnauthorized)
return