fix(key-auth): change hide_credentials behaviour #14656
Open
+10
−2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Change key-auth plugin "hide_credentials" parameter behaviour.
Before proposed change, "hide_credentials" parameter of key-auth plugin makes "apikey" parameter removed from both headers and query_string regardless of search locations. This very simple fix allows to remove apikey from query and/or from headers accordingly to search locations.
This is required for me as I have some API backends that rely on a "apikey" value set as header, and the Kong gateway is set to find the "apikey" in query.
Fix:
Checklist
Successfully tested.
Code change is obvious and does not require a full test spec.
Issue reference