fix: keystone panic on invalid auth token

This commit is contained in:
Qiu Jian
2019-09-25 21:01:53 +08:00
parent 833cf47f11
commit 2109fd29a6
+1 -1
View File
@@ -179,7 +179,7 @@ func verifyTokensV3(ctx context.Context, w http.ResponseWriter, r *http.Request)
func verifyCommon(ctx context.Context, w http.ResponseWriter, tokenStr string) (*SAuthToken, error) {
adminToken := policy.FetchUserCredential(ctx)
if !adminToken.IsAllow(rbacutils.ScopeSystem, api.SERVICE_TYPE, "tokens", "perform", "auth") {
if adminToken == nil || !adminToken.IsAllow(rbacutils.ScopeSystem, api.SERVICE_TYPE, "tokens", "perform", "auth") {
return nil, httperrors.NewForbiddenError("not allow to auth")
}
token := SAuthToken{}