Skip to content

fix: Auth token verification failure should not throw error immedicately#234

Merged
kurtisvg merged 1 commit into
mainfrom
oauth-bug
Jan 24, 2025
Merged

fix: Auth token verification failure should not throw error immedicately#234
kurtisvg merged 1 commit into
mainfrom
oauth-bug

Conversation

@duwenxin99

Copy link
Copy Markdown
Contributor

Currently, we are throwing 401 error immediately after auth token verification failure. This is not expected in the following situations:

  1. Non-auth tool invocation with auth token that is invalid.
  2. Auth tool invocation with all the required auth token, but the header contains extra non-required token that is invalid
    These requests should pass the authorization check but fail under the current implementation.

Change made in this PR:

  1. Do not throw error immediately after auth token verification failure. Instead only log it and continue to the next header iteration.
  2. In the parseParams() method, if an auth parameter is missing, we should error with the message telling the user that either the auth header is missing or is invalid.

@kurtisvg kurtisvg merged commit 4639cc6 into main Jan 24, 2025
@kurtisvg kurtisvg deleted the oauth-bug branch January 24, 2025 15:49
Yuan325 pushed a commit that referenced this pull request Feb 6, 2025
🤖 I have created a release *beep* *boop*
---


##
[0.1.0](v0.0.5...v0.1.0)
(2025-02-06)


### ⚠ BREAKING CHANGES

* **langchain-sdk:** The SDK for `toolbox-langchain` is now located
[here](https://github.com/googleapis/genai-toolbox-langchain-python).

### Features

* Add Cloud SQL for SQL Server Source and Tool
([#223](#223))
([9bad952](9bad952))
* Add Cloud SQL for MySQL Source and Tool
([#221](#221))
([f1f61d7](f1f61d7))
* Add Dgraph Source and Tool
([#233](#233))
([617cc87](617cc87))
* Add local quickstart
([#232](#232))
([497fb06](497fb06))
* Add user agents for cloud sources
([#244](#244))
([8452f8e](8452f8e))
* Add MySQL Source
([#250](#250))
([378692a](378692a))
* Add MSSQL source
([#255](#255))
([8fca0a9](8fca0a9))


### Bug Fixes

* Auth token verification failure should not throw error immediately
([#234](#234))
([4639cc6](4639cc6))
* Fix typo in postgres test
([#216](#216))
([0c3d12a](0c3d12a))
* **mssql:** Fix mssql tool kind to mssql-sql
([#249](#249))
([1357be2](1357be2))
* **mysql:** Fix mysql tool kind to mysql-sql
([#248](#248))
([669d6b7](669d6b7))
* Schema float type
([#264](#264))
([1702f74](1702f74))
* Typos at test cases
([#265](#265))
([b7c5661](b7c5661))
* Update README and quickstart with the correct async APIs.
([#269](#269))
([21eef2e](21eef2e))
* Update tool invoke to return json
([#266](#266))
([ad58cd5](ad58cd5))

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Kurtis Van Gent <31518063+kurtisvg@users.noreply.github.com>
jeffreyrubi pushed a commit to jeffreyrubi/genai-toolbox that referenced this pull request Jun 7, 2025
…ely (googleapis#234)

Currently, we are throwing 401 error immediately after auth token
verification failure. This is not expected in the following situations:
1. Non-auth tool invocation with auth token that is invalid.
2. Auth tool invocation with all the required auth token, but the header
contains extra non-required token that is invalid
These requests should pass the authorization check but fail under the
current implementation.

Change made in this PR:
1. Do not throw error immediately after auth token verification failure.
Instead only log it and continue to the next header iteration.
2. In the parseParams() method, if an auth parameter is missing, we
should error with the message telling the user that either the auth
header is missing or is invalid.
jeffreyrubi pushed a commit to jeffreyrubi/genai-toolbox that referenced this pull request Jun 7, 2025
🤖 I have created a release *beep* *boop*
---


##
[0.1.0](googleapis/mcp-toolbox@v0.0.5...v0.1.0)
(2025-02-06)


### ⚠ BREAKING CHANGES

* **langchain-sdk:** The SDK for `toolbox-langchain` is now located
[here](https://github.com/googleapis/genai-toolbox-langchain-python).

### Features

* Add Cloud SQL for SQL Server Source and Tool
([googleapis#223](googleapis#223))
([9bad952](googleapis@9bad952))
* Add Cloud SQL for MySQL Source and Tool
([googleapis#221](googleapis#221))
([f1f61d7](googleapis@f1f61d7))
* Add Dgraph Source and Tool
([googleapis#233](googleapis#233))
([617cc87](googleapis@617cc87))
* Add local quickstart
([googleapis#232](googleapis#232))
([497fb06](googleapis@497fb06))
* Add user agents for cloud sources
([googleapis#244](googleapis#244))
([8452f8e](googleapis@8452f8e))
* Add MySQL Source
([googleapis#250](googleapis#250))
([378692a](googleapis@378692a))
* Add MSSQL source
([googleapis#255](googleapis#255))
([8fca0a9](googleapis@8fca0a9))


### Bug Fixes

* Auth token verification failure should not throw error immediately
([googleapis#234](googleapis#234))
([4639cc6](googleapis@4639cc6))
* Fix typo in postgres test
([googleapis#216](googleapis#216))
([0c3d12a](googleapis@0c3d12a))
* **mssql:** Fix mssql tool kind to mssql-sql
([googleapis#249](googleapis#249))
([1357be2](googleapis@1357be2))
* **mysql:** Fix mysql tool kind to mysql-sql
([googleapis#248](googleapis#248))
([669d6b7](googleapis@669d6b7))
* Schema float type
([googleapis#264](googleapis#264))
([1702f74](googleapis@1702f74))
* Typos at test cases
([googleapis#265](googleapis#265))
([b7c5661](googleapis@b7c5661))
* Update README and quickstart with the correct async APIs.
([googleapis#269](googleapis#269))
([21eef2e](googleapis@21eef2e))
* Update tool invoke to return json
([googleapis#266](googleapis#266))
([ad58cd5](googleapis@ad58cd5))

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Kurtis Van Gent <31518063+kurtisvg@users.noreply.github.com>
NightStack15 added a commit to NightStack15/googleapis-_-genai-toolbox that referenced this pull request Mar 20, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.1.0](googleapis/mcp-toolbox@v0.0.5...v0.1.0)
(2025-02-06)


### ⚠ BREAKING CHANGES

* **langchain-sdk:** The SDK for `toolbox-langchain` is now located
[here](https://github.com/googleapis/genai-toolbox-langchain-python).

### Features

* Add Cloud SQL for SQL Server Source and Tool
([#223](googleapis/mcp-toolbox#223))
([9bad952](googleapis/mcp-toolbox@9bad952))
* Add Cloud SQL for MySQL Source and Tool
([#221](googleapis/mcp-toolbox#221))
([f1f61d7](googleapis/mcp-toolbox@f1f61d7))
* Add Dgraph Source and Tool
([#233](googleapis/mcp-toolbox#233))
([617cc87](googleapis/mcp-toolbox@617cc87))
* Add local quickstart
([#232](googleapis/mcp-toolbox#232))
([497fb06](googleapis/mcp-toolbox@497fb06))
* Add user agents for cloud sources
([#244](googleapis/mcp-toolbox#244))
([8452f8e](googleapis/mcp-toolbox@8452f8e))
* Add MySQL Source
([#250](googleapis/mcp-toolbox#250))
([378692a](googleapis/mcp-toolbox@378692a))
* Add MSSQL source
([#255](googleapis/mcp-toolbox#255))
([8fca0a9](googleapis/mcp-toolbox@8fca0a9))


### Bug Fixes

* Auth token verification failure should not throw error immediately
([#234](googleapis/mcp-toolbox#234))
([4639cc6](googleapis/mcp-toolbox@4639cc6))
* Fix typo in postgres test
([#216](googleapis/mcp-toolbox#216))
([0c3d12a](googleapis/mcp-toolbox@0c3d12a))
* **mssql:** Fix mssql tool kind to mssql-sql
([#249](googleapis/mcp-toolbox#249))
([1357be2](googleapis/mcp-toolbox@1357be2))
* **mysql:** Fix mysql tool kind to mysql-sql
([#248](googleapis/mcp-toolbox#248))
([669d6b7](googleapis/mcp-toolbox@669d6b7))
* Schema float type
([#264](googleapis/mcp-toolbox#264))
([1702f74](googleapis/mcp-toolbox@1702f74))
* Typos at test cases
([#265](googleapis/mcp-toolbox#265))
([b7c5661](googleapis/mcp-toolbox@b7c5661))
* Update README and quickstart with the correct async APIs.
([#269](googleapis/mcp-toolbox#269))
([21eef2e](googleapis/mcp-toolbox@21eef2e))
* Update tool invoke to return json
([#266](googleapis/mcp-toolbox#266))
([ad58cd5](googleapis/mcp-toolbox@ad58cd5))

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Kurtis Van Gent <31518063+kurtisvg@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants