I tried using an APAT to generate a manifest. This is not yet supported, see epic #8345, so it failed as expected. Except I didn't remember that fact and looked for a log message explaining the 401 response. There is none. Worse than that, the APAT makes it all the way into the service layer and is rejected there, leading to more confusing logs, and a somewhat misleading error message in the response body.
(Evidence below updated by Claude Code)
It shows that the APAT is first used as part of a DynamoDB cache key, then sent to Google's tokeninfo endpoint as if it were an OAuth 2.0 access token. Google rejects it, and the only explanation in the log is Invalid credentials from azul.terra — which is misleading, since the APAT is valid and merely unsupported by this endpoint.
Abridged log for that request, one line per event, with the token elided:
azul.chalice Received PUT request for '/fetch/manifest/files', with
{"query": {"catalog": "anvil", "filters": "{}", "format": "verbatim.pfb"}, …}
azul.chalice Authenticated request as PersonalAccessTokenAuthentication(token='…')
azul.boto3 dynamodb.GetItem: … {"TableName": "azul-sources_cache_by_auth-anvildev",
"Key": {"identity": {"S": "anvil:…"}}, "ProjectionExpression": "sources,expiration"}
azul.boto3 dynamodb.GetItem: Got 200 response
azul.boto3 dynamodb.GetItem: … with a response body of length 2 being b'{}'
azul.oauth2 Making GET request to 'https://www.googleapis.com/oauth2/v3/tokeninfo?access_token=…'
azul.oauth2 … with a response body of length 43 being b'{\n "error_description": "Invalid Value"\n}\n'
azul.oauth2 Got 400 response after 0.149s from GET to https://www.googleapis.com/oauth2/v3/tokeninfo?access_token=…
azul.terra Invalid credentials
Traceback (most recent call last):
File "/var/task/azul/service/source_service.py", line 193, in _get
result = response['Item']
KeyError: 'Item'
During handling of the above exception, another exception occurred:
…
azul.chalice Returning 401 response with headers {…}
azul.chalice … with a response body of length 63 being
{"Code": "UnauthorizedError", "Message": "Invalid credentials"}
I tried using an APAT to generate a manifest. This is not yet supported, see epic #8345, so it failed as expected. Except I didn't remember that fact and looked for a log message explaining the 401 response. There is none. Worse than that, the APAT makes it all the way into the service layer and is rejected there, leading to more confusing logs, and a somewhat misleading error message in the response body.
(Evidence below updated by Claude Code)
It shows that the APAT is first used as part of a DynamoDB cache key, then sent to Google's
tokeninfoendpoint as if it were an OAuth 2.0 access token. Google rejects it, and the only explanation in the log isInvalid credentialsfromazul.terra— which is misleading, since the APAT is valid and merely unsupported by this endpoint.Abridged log for that request, one line per event, with the token elided: