comparison mod_http_oauth2/mod_http_oauth2.lua @ 5335:53c6f49dcbb8

mod_http_oauth2: Correct error code when missing credentials for userinfo
author Kim Alvefur <zash@zash.se>
date Mon, 10 Apr 2023 10:44:23 +0200
parents eb482defd9b0
children 77ac04bd2f65
comparison
equal deleted inserted replaced
5334:3c51eab0afe8 5335:53c6f49dcbb8
748 748
749 local function handle_userinfo_request(event) 749 local function handle_userinfo_request(event)
750 local request = event.request; 750 local request = event.request;
751 local credentials = get_request_credentials(request); 751 local credentials = get_request_credentials(request);
752 if not credentials or not credentials.bearer_token then 752 if not credentials or not credentials.bearer_token then
753 return 400; 753 return 401;
754 end 754 end
755 local token_info = tokens.get_token_info(credentials.bearer_token); 755 local token_info = tokens.get_token_info(credentials.bearer_token);
756 if not token_info then 756 if not token_info then
757 return 403; 757 return 403;
758 end 758 end