Skip to content

Pulpcore returns 403 instead of 401 on failed authentication #7994

Description

@YakBizzarro

Version
Base docker image: pulp-minimal at version 3.113.0

  • Storage backend:
    • s3 extension for pulpcore (3.113.0)
  • Keycloak integration:
    • social-auth-core (4.9.1)
    • social-auth-app-django (5.9.0)
  • Removed inactive plugins, leaving only:
    • pulp_file
    • pulp_python
    • pulp_container

Describe the bug
Similarly to #3730, if a user try to fetch a Python package wheel from a pulp private PyPI registry without authentication, Pulp returns 403 Forbidden instead of 401 Unauthorized as expected.

To Reproduce
Steps to reproduce the behavior:
Setup Pulp to provide a private PyPI repository.
Try to fetch a wheel without providing any authentication:
curl https://example.com/pulp/content/example-packages/example-1.0.0-py3-none-any.whl
Observe it returns a 403 error

Expected behavior
If the user ask for a protected resource without providing credentials, it should get a 401 error rather than a 403

Additional context
This is relevant for pip, since if keyring is used to retrieve the full credentials (username+password), it needs the correct error code (401) to realize the registry needs authentication. See pypa/pip#11721.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions