[PR #5678] [management] Allow multiple header auths with same header name #23641

Closed
opened 2026-08-05 06:07:28 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/5678

State: closed
Merged: Yes


Describe your changes

  • Remove duplicate canonical header name check from validateHeaderAuths, allowing multiple header auth entries with the same header name (e.g. two Bearer tokens on Authorization for secret rotation)
  • Add validation tests for header auths (valid cases, rejections, disabled entries)
  • Add proxy middleware test verifying OR semantics for multiple values on the same header

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (API schema unchanged, only server-side validation relaxed)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • New Features

    • Removed restriction preventing multiple header authentication entries with the same canonical header name. Users can now configure multiple credential values for authentication under the same header.
  • Tests

    • Added comprehensive test coverage for header authentication validation, including scenarios with multiple values under the same header and various edge cases.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/5678 **State:** closed **Merged:** Yes --- ## Describe your changes - Remove duplicate canonical header name check from `validateHeaderAuths`, allowing multiple header auth entries with the same header name (e.g. two Bearer tokens on Authorization for secret rotation) - Add validation tests for header auths (valid cases, rejections, disabled entries) - Add proxy middleware test verifying OR semantics for multiple values on the same header ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [x] Is a feature enhancement - [ ] It is a refactor - [x] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (API schema unchanged, only server-side validation relaxed) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Removed restriction preventing multiple header authentication entries with the same canonical header name. Users can now configure multiple credential values for authentication under the same header. * **Tests** * Added comprehensive test coverage for header authentication validation, including scenarios with multiple values under the same header and various edge cases. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 06:07:28 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#23641