Skip to content

fix: reject error-key authorization results - #959

Closed
anttiviljami wants to merge 2 commits into
mainfrom
fix/reject-error-key-auth-results
Closed

fix: reject error-key authorization results#959
anttiviljami wants to merge 2 commits into
mainfrom
fix/reject-error-key-auth-results

Conversation

@anttiviljami

Copy link
Copy Markdown
Member

Summary

  • treat any returned object containing an error key as failed authorization
  • cover falsy and multi-key error results with regression tests

This hardens the existing fix for GHSA-j939-289f-wq4w.

@anttiviljami

Copy link
Copy Markdown
Member Author

Closing as obsolete: the requested multi-key error handling is already present on main, and falsy error values intentionally represent successful authorization. The PR no longer contains a functional change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant