Skip to content

fix: lower log level for missing authorization header - #105

Open
septydev wants to merge 1 commit into
auth0:masterfrom
septydev:fix/dpop-missing-auth-log-level
Open

septydev wants to merge 1 commit into
auth0:masterfrom
septydev:fix/dpop-missing-auth-log-level

Conversation

@septydev

Copy link
Copy Markdown

✏️ Changes

In DPoP required mode, a missing Authorization header was logged at Error level because it was handled together with invalid header counts.

This change distinguishes the missing-header case from malformed requests:

  • requests without an Authorization header are logged at Debug
  • invalid header counts continue to be logged at Error
  • authentication behavior remains unchanged

A unit test was added for the missing-header case.

🔗 References

Fixes #104

🎯 Testing

  • This change adds unit test coverage
  • This change adds integration test coverage
  • This change has been tested on the latest version of the platform/language

Validated with:

  • targeted MessageReceivedHandlerTests: 21 passed
  • Release build
  • full unit suite: 610 passed, 1 unrelated pre-existing failure
  • the same failing cache test reproduces on upstream/master
  • git diff --check

✅ Checklist

  • I have read the Auth0 general contribution guidelines
  • I have read the Auth0 Code of Conduct
  • All changes related to this fix are covered by tests
  • All commits are signed

@septydev
septydev requested a review from a team as a code owner September 14, 2026 18:23

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DPoP MessageReceivedHandler logs at Error for every request without an Authorization header, including anonymous endpoints

1 participant