Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Fixes exception recursion error when handling a bad
Authorization
header; fixes #466Detailed description
When a token failed due to malformed/expired token or malformed header, this would result in an error page. But the error handler was also trying to get the active user, which in turn was trying to parse the bad header. This led to an overall failure.
The fix was to make use of the already-existing
token_error
field on the context which informs us that the token already failed to parse, and to makeuser.get_active()
returnNone
.Developer/user impact
Test plan
Manually tested with invalid, expired, malformed, and valid tokens via
curl -H
.Got a site to show off?