fix(actions): return 401 for unregistered runner (#39578) (#39585)

Backport #39578

Signed-off-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: Dr Alex Mitre <bedr10_capacitacion@hotmail.com>
Co-authored-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
Giteabot
2026-10-04 04:58:32 -07:00
committed by GitHub
co-authored by Dr Alex Mitre Alex Mitre wxiaoguang
parent 3ee1924069
commit 0ca36eeb3c
+5 -2
View File
@@ -27,6 +27,9 @@ const (
)
var withRunner = connect.WithInterceptors(connect.UnaryInterceptorFunc(func(unaryFunc connect.UnaryFunc) connect.UnaryFunc {
// A plain gRPC status.Error is treated as unknown by Connect and becomes HTTP 500
// To respond an HTTP status code, use connect.Error instead
errUnregisteredRunner := connect.NewError(connect.CodeUnauthenticated, errors.New("unregistered runner"))
return func(ctx context.Context, request connect.AnyRequest) (connect.AnyResponse, error) {
methodName := getMethodName(request)
if methodName == "Register" {
@@ -38,12 +41,12 @@ var withRunner = connect.WithInterceptors(connect.UnaryInterceptorFunc(func(unar
runner, err := actions_model.GetRunnerByUUID(ctx, uuid)
if err != nil {
if errors.Is(err, util.ErrNotExist) {
return nil, status.Error(codes.Unauthenticated, "unregistered runner")
return nil, errUnregisteredRunner
}
return nil, status.Error(codes.Internal, err.Error())
}
if !util.CryptoConstTimeEqual(runner.TokenHash, auth_model.HashToken(token, runner.TokenSalt)) {
return nil, status.Error(codes.Unauthenticated, "unregistered runner")
return nil, errUnregisteredRunner
}
now := time.Now()