Skip to content

Commit ae9cb43

Browse files
committed
Fix bug in RegistryRequiresAuth
1 parent 87a7d14 commit ae9cb43

2 files changed

Lines changed: 9 additions & 2 deletions

File tree

‎internal/dockerauth/dockerauth.go‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -226,6 +226,10 @@ func (d *DockerAuth) RegistryRequiresAuth(ctx context.Context, registry string)
226226

227227
tr, err := transport.NewWithContext(ctx, reg, authn.Anonymous, http.DefaultTransport, []string{repo.Scope("pull")})
228228
if err != nil {
229+
var te *transport.Error
230+
if errors.As(err, &te) && requiresAuth(te.StatusCode) {
231+
return true, nil
232+
}
229233
return true, fmt.Errorf("negotiating anonymous access to %s: %w", host, err)
230234
}
231235

@@ -244,12 +248,16 @@ func (d *DockerAuth) RegistryRequiresAuth(ctx context.Context, registry string)
244248
if resp.StatusCode >= http.StatusOK && resp.StatusCode < http.StatusMultipleChoices {
245249
return false, nil
246250
}
247-
if resp.StatusCode == http.StatusUnauthorized || resp.StatusCode == http.StatusForbidden || resp.StatusCode == http.StatusNotFound {
251+
if requiresAuth(resp.StatusCode) {
248252
return true, nil
249253
}
250254
return true, fmt.Errorf("unexpected status %s from %s", resp.Status, host)
251255
}
252256

257+
func requiresAuth(code int) bool {
258+
return code == http.StatusUnauthorized || code == http.StatusForbidden || code == http.StatusNotFound
259+
}
260+
253261
// CreatePullSecretYAMLFromCredentials creates Kubernetes pull secret YAML from
254262
// verified credentials, scoped to the host of the given image registry
255263
func (d *DockerAuth) CreatePullSecretYAMLFromCredentials(creds Credentials, namespace, registry string) string {

‎internal/dockerauth/dockerauth_test.go‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,6 @@ func TestRegistryRequiresAuth(t *testing.T) {
149149
challengeAuth: true,
150150
tokenStatus: http.StatusUnauthorized,
151151
expectedRequires: true,
152-
expectErr: true,
153152
},
154153
{
155154
name: "tags-list request returns an unexpected server error",

0 commit comments

Comments
 (0)