fix(auth): reject unsigned admin identity headers

This commit is contained in:
elky
2026-08-18 11:12:17 +08:00
parent b45df89ce4
commit 535ee098c3
2 changed files with 83 additions and 0 deletions
@@ -177,6 +177,19 @@ fn extract_trusted_auth_headers(headers: &http::HeaderMap) -> Option<GatewayTrus
})
}
#[cfg(not(test))]
pub(super) fn extract_trusted_admin_headers(
_headers: &http::HeaderMap,
) -> Option<GatewayTrustedAdminHeaders> {
// The public gateway has no authenticated upstream that is allowed to
// assert an administrator principal. `x-aether-gateway` is also emitted
// on public responses, so it cannot serve as proof that these headers were
// produced by a trusted hop. Production requests must authenticate with a
// real admin session or management bearer token instead.
None
}
#[cfg(test)]
pub(super) fn extract_trusted_admin_headers(
headers: &http::HeaderMap,
) -> Option<GatewayTrustedAdminHeaders> {