mirror of
https://github.com/docker/cli.git
synced 2026-09-28 02:06:53 -04:00
registry: map login HTTP status through errhttp.ToNative
translateV2AuthError only unwraps a url.Error from Do(); a 401 status never went through it. Use errhttp.ToNative so Auth() treats that 401 as unauthorized and stops. Signed-off-by: Dean Chen <862469039@qq.com> Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
This commit is contained in:
@@ -8,6 +8,7 @@ import (
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/containerd/errdefs/pkg/errhttp"
|
||||
"github.com/containerd/log"
|
||||
"github.com/docker/distribution/registry/client/auth"
|
||||
"github.com/docker/distribution/registry/client/auth/challenge"
|
||||
@@ -67,11 +68,7 @@ func loginV2(ctx context.Context, authConfig *registry.AuthConfig, endpoint APIE
|
||||
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
// TODO(dmcgowan): Attempt to further interpret result, status code and error code string
|
||||
err := fmt.Errorf("login attempt to %s failed with status: %d %s", endpointStr, resp.StatusCode, http.StatusText(resp.StatusCode))
|
||||
if resp.StatusCode == http.StatusUnauthorized {
|
||||
return "", unauthorizedErr{err}
|
||||
}
|
||||
return "", err
|
||||
return "", fmt.Errorf("login attempt to %s failed with status: %d %s: %w", endpointStr, resp.StatusCode, http.StatusText(resp.StatusCode), errhttp.ToNative(resp.StatusCode))
|
||||
}
|
||||
|
||||
return credentialAuthConfig.IdentityToken, nil
|
||||
|
||||
@@ -33,6 +33,7 @@ func TestLoginV2BasicAuthUnauthorized(t *testing.T) {
|
||||
_, err = loginV2(ctx, ®istry.AuthConfig{Username: "alice", Password: "wrong"}, endpoint, "docker-test")
|
||||
assert.ErrorContains(t, err, "401")
|
||||
assert.Check(t, errdefs.IsUnauthorized(err))
|
||||
assert.Check(t, is.ErrorType(err, errdefs.IsUnauthorized))
|
||||
|
||||
token, err := loginV2(ctx, ®istry.AuthConfig{Username: "alice", Password: "secret"}, endpoint, "docker-test")
|
||||
assert.NilError(t, err)
|
||||
|
||||
Reference in New Issue
Block a user