fix: jwt error return status 400 for invalid role (#4081)

This commit is contained in:
Taimoor Zaeem
2025-05-13 15:09:25 -05:00
committed by GitHub
parent 1609e32c3a
commit 8390df0fa5
4 changed files with 10 additions and 3 deletions
+1 -1
View File
@@ -212,7 +212,7 @@ jwtaudroleclaims:
- key: '.aud[1]' # succeeds the aud claims check, but fail when hits the db
data:
aud: [postgrest_test_author, postgrest_test_invalid]
expected_status: 400
expected_status: 401
invalidroleclaimkeys:
- 'role.other'
+1 -2
View File
@@ -96,8 +96,7 @@ def test_jwt_errors(defaultenv):
headers = jwtauthheader({"role": "not_existing"}, SECRET)
response = postgrest.session.get("/", headers=headers)
# TODO: Should this return 401?
assert response.status_code == 400
assert response.status_code == 401
assert response.json()["message"] == 'role "not_existing" does not exist'
# -31 seconds, because we allow clock skew of 30 seconds