Duansg opened a new pull request, #4442: URL: https://github.com/apache/hertzbeat/pull/4442
## What's changed? Sureness accepts a JWT from either the `Authorization` header or the `token` query parameter. The managed API token check (#4080) only read the header, so it skipped tokens passed as a query parameter. This PR: - Validates every managed JWT the request carries, from both the Bearer header and the `token` query parameter. - Extracts the Bearer token exactly as Sureness does, so the check validates the token that Sureness authenticated. - Rejects a managed subject with 401 when its token cannot be resolved. Login tokens, legacy tokens and excluded resources behave as before. ## Checklist - [x] I have read the [Contributing Guide](https://hertzbeat.apache.org/docs/community/code_style_and_quality_guide) - [ ] I have written the necessary doc or comment. - [x] I have added the necessary unit tests and all cases have passed. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
