Improve Docker redirect and auth header handling

Adds special handling for Docker registry redirects to prevent leaking Authorization headers to S3 or blob storage by using manual redirect mode and stripping sensitive headers before following redirects. Refactors scope handling for unauthorized responses and ensures retry logic for token fetches also respects Docker redirect requirements.
This commit is contained in:
xixu-me committed 2025-12-12 13:29:07 +08:00
1 parent 9fc2804332
commit 29fe048984
2 files changed
+55 -27

No files matched your search

+3 -7
View File
@@ -131,16 +131,12 @@ export function getScopeFromUrl(url, effectivePath, platform) {
* Generates a Docker/OCI registry-compliant 401 response with a WWW-Authenticate
* header that directs clients to the token authentication endpoint.
* @param {URL} url - Request URL used to construct authentication realm
* @param {string} [scope] - Optional scope to include in the challenge
* @param {URL} url - Request URL used to construct authentication realm
* @returns {Response} Unauthorized response with WWW-Authenticate header
*/
export function responseUnauthorized(url, scope) {
export function responseUnauthorized(url) {
const headers = new Headers();
let authHeader = `Bearer realm="https://${url.hostname}/v2/auth",service="Xget"`;
if (scope) {
authHeader += `,scope="${scope}"`;
}
headers.set('WWW-Authenticate', authHeader);
headers.set('WWW-Authenticate', `Bearer realm="https://${url.hostname}/v2/auth",service="Xget"`);
return new Response(JSON.stringify({
errors: [{
code: 'UNAUTHORIZED',