Skip to content

fix(session): match the Bearer scheme case-insensitively - #195

Merged
allen0099 merged 1 commit into
masterfrom
fix/bearer-scheme-case-insensitive
Sep 26, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/bearer-scheme-case-insensitive

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Closes #166.

Problem

The session middleware (FastAPICacheXSessionMiddleware and the deprecated SessionMiddleware, through _extract_header_token) read the bearer token with auth_header.startswith("Bearer "). Authentication scheme names are case-insensitive (RFC 9110 §11.1), so these headers got no session:

Authorization before after
Bearer tok "tok" "tok"
bearer tok / BEARER tok None "tok"
Bearer tok (two spaces, allowed by RFC 6750 §2.1) " tok" "tok"
Bearer "" None

Change

  • Split the header on the first space, and compare the scheme case-insensitively.
  • Strip the extra spaces before the token.
  • Return a token only when one is present. An empty bearer header now falls through to the next source in token_source_priority, as an empty custom header already does.

Tests

  • New parametrized tests cover the scheme in several cases, extra spaces, and headers that are empty or use another scheme.
  • Mutation check: with the fix reverted, exactly the five new cases that differ fail.
  • middleware.py coverage stays at 100%.

Authentication scheme names are case-insensitive (RFC 9110 11.1), but the
middleware only recognised the exact "Bearer " prefix, so a client sending
"bearer <token>" got no session. Accept one or more spaces before the token
(RFC 6750 2.1), and yield no token for a header that carries none.

Closes #166
@allen0099 allen0099 added this to the 0.3.8 milestone Sep 26, 2026
@allen0099 allen0099 added bug Something isn't working session Session management subsystem labels Sep 26, 2026
@allen0099
allen0099 merged commit e8849ff into master Sep 26, 2026
11 checks passed
@allen0099
allen0099 deleted the fix/bearer-scheme-case-insensitive branch September 26, 2026 12:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working session Session management subsystem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Match the Authorization scheme case-insensitively

1 participant