Commit b356195
authored
fix: Ensure that numtracker headers are not re-used (#1202)
If the headers are only set when they are present but not cleared at the
end of a plan (or when they're absent), a request with no headers
following a request with headers will re-use the previous users
credentials allowing unauthenticated access to running plans.
Setting the headers to an empty map if none are present helps ensure
tokens cannot be used by other users.1 parent 0760be5 commit b356195
File tree
2 files changed
+40
-2
lines changed- src/blueapi/service
- tests/unit_tests/service
2 files changed
+40
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
224 | 224 | | |
225 | 225 | | |
226 | 226 | | |
227 | | - | |
228 | | - | |
| 227 | + | |
229 | 228 | | |
230 | 229 | | |
231 | 230 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
418 | 418 | | |
419 | 419 | | |
420 | 420 | | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
421 | 460 | | |
422 | 461 | | |
423 | 462 | | |
| |||
0 commit comments