Skip to content

fix: reject empty bearer tokens - #430

Open
lprnmns wants to merge 1 commit into
fastify:mainfrom
lprnmns:fix/reject-empty-bearer-token-human-dco
Open

lprnmns wants to merge 1 commit into
fastify:mainfrom
lprnmns:fix/reject-empty-bearer-token-human-dco

Conversation

@lprnmns

@lprnmns lprnmns commented Aug 31, 2026

Copy link
Copy Markdown

Problem

An empty Bearer credential (Authorization: Bearer ) currently reaches token decoding and returns HTTP 500 with missing token. This malformed authentication input should use the existing HTTP 400 Bad Request path.

Fix

Require a non-empty token before accepting the two-part Bearer header. The existing FST_JWT_BAD_REQUEST error and message are reused.

Tests

  • node --test test/malformed-authorization.test.js - passed after the fix; the pre-fix run failed with 500 !== 400
  • npm test - passed; 179 unit tests, 100% coverage, and 44 TSTyche assertions
  • Adjacent valid/empty Bearer runtime probe - passed; valid token remained HTTP 200 and empty token became HTTP 400
  • git diff --check - passed

Compatibility

Only an empty Bearer value changes behavior. Valid Bearer tokens and the other authentication branches remain covered by the full suite.

Related issue

Independent reproduction; final searches found no matching open issue or pull request.

Signed-off-by: lprnmns <manasalperen@gmail.com>
@lprnmns
lprnmns marked this pull request as ready for review August 31, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant