diff --git a/pkg/keystone/tokens/handlers.go b/pkg/keystone/tokens/handlers.go index 520a5267dc..b218529636 100644 --- a/pkg/keystone/tokens/handlers.go +++ b/pkg/keystone/tokens/handlers.go @@ -179,7 +179,7 @@ func verifyTokensV3(ctx context.Context, w http.ResponseWriter, r *http.Request) func verifyCommon(ctx context.Context, w http.ResponseWriter, tokenStr string) (*SAuthToken, error) { adminToken := policy.FetchUserCredential(ctx) - if !adminToken.IsAllow(rbacutils.ScopeSystem, api.SERVICE_TYPE, "tokens", "perform", "auth") { + if adminToken == nil || !adminToken.IsAllow(rbacutils.ScopeSystem, api.SERVICE_TYPE, "tokens", "perform", "auth") { return nil, httperrors.NewForbiddenError("not allow to auth") } token := SAuthToken{}