Skip to content

fix(middleware): read body-layer credentials from the verifier header - #419

Merged
mattsse merged 2 commits into
tempoxyz:mainfrom
kriss39:fix/body-layer-credential-header
Sep 30, 2026
Merged

mattsse merged 2 commits into
tempoxyz:mainfrom
kriss39:fix/body-layer-credential-header

Conversation

@kriss39

@kriss39 kriss39 commented Sep 13, 2026

Copy link
Copy Markdown
Contributor

#400 added PaymentVerifier::credential_header() and made PaymentService read the credential from it, so an Mpp built with requires_auth(true) advertises header="Payment-Authorization" and leaves Authorization to the application. PaymentBodyService::call was not updated and still reads header::AUTHORIZATION.

With PaymentBodyLayer::charge(&mpp, ..) on such an Mpp, a client that follows the challenge and sends Payment-Authorization: Payment … (with its own Authorization: Bearer …) gets a fresh 402 back on every attempt: the layer never sees the credential, and extract_payment_scheme on the bearer token yields None. Body-bound payments are simply unverifiable in that configuration.

One-line fix (get(verifier.credential_header()), matching PaymentService), plus two tests using a body-aware verifier that returns Payment-Authorization: a credential in the advertised header verifies and replays the body, and a credential left in Authorization is ignored, as it already is in PaymentService. Both fail on main.

PaymentService reads the credential from `verifier.credential_header()`
(added in tempoxyz#400 so `requires_auth` servers can keep `Authorization` for
their own auth), but PaymentBodyService still hard-coded
`Authorization`. A `PaymentBodyLayer` over an `Mpp` with
`requires_auth(true)` issues challenges advertising
`header="Payment-Authorization"`, then never looks at that header, so
a conforming client is answered with a fresh 402 on every retry.

Use the verifier's header in the body layer as well.
@kriss39

kriss39 commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

@brendanjryan gentle ping on this one when you have time.

@mattsse mattsse left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@mattsse
mattsse enabled auto-merge (squash) September 30, 2026 13:33
@mattsse
mattsse merged commit 11ed1bc into tempoxyz:main Sep 30, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants