fix: revert explicit apikey header (caused Kong duplicate-apikey 401)
api-ci-deploy / test-build-deploy (push) Has been cancelled
api-ci-deploy / test-build-deploy (push) Has been cancelled
The previous commit added apikey to _create_base_client headers, but supabase-py already sets apikey from the key arg → two apikey headers → Kong rejected every as-user call with 401 'Duplicate API key found' (exam API 502'd on auth). Revert to Authorization-only; fix the two header unit tests to assert the real contract (apikey via the key arg; options.headers carries only the user Authorization). Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
f3da9f3b59
commit
93972a62f7
@@ -26,8 +26,10 @@ def test_supabase_anon_for_user_sets_user_authorization_header(monkeypatch):
|
||||
|
||||
client_module.SupabaseAnonClient.for_user('Bearer user-jwt')
|
||||
|
||||
# apikey comes from the `key` arg (supabase-py sets the apikey header); options.headers must
|
||||
# carry only the user Authorization override. A second apikey here → Kong "Duplicate API key".
|
||||
assert captured['key'] == 'anon-key'
|
||||
assert captured['options'].headers['apikey'] == 'anon-key'
|
||||
assert 'apikey' not in captured['options'].headers
|
||||
assert captured['options'].headers['Authorization'] == 'Bearer user-jwt'
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user