Skip to content

Controllers not supporting APATs don't reject them early #8367

Description

@hannes-ucsc

I tried using an APAT to generate a manifest. This is not yet supported, see epic #8345, so it failed as expected. Except I didn't remember that fact and looked for a log message explaining the 401 response. There is none. Worse than that, the APAT makes it all the way into the service layer and is rejected there, leading to more confusing logs, and a somewhat misleading error message in the response body.

(Evidence below updated by Claude Code)

It shows that the APAT is first used as part of a DynamoDB cache key, then sent to Google's tokeninfo endpoint as if it were an OAuth 2.0 access token. Google rejects it, and the only explanation in the log is Invalid credentials from azul.terra — which is misleading, since the APAT is valid and merely unsupported by this endpoint.

Abridged log for that request, one line per event, with the token elided:

azul.chalice   Received PUT request for '/fetch/manifest/files', with
                 {"query": {"catalog": "anvil", "filters": "{}", "format": "verbatim.pfb"}, …}
azul.chalice   Authenticated request as PersonalAccessTokenAuthentication(token='…')
azul.boto3     dynamodb.GetItem: … {"TableName": "azul-sources_cache_by_auth-anvildev",
                 "Key": {"identity": {"S": "anvil:…"}}, "ProjectionExpression": "sources,expiration"}
azul.boto3     dynamodb.GetItem: Got 200 response
azul.boto3     dynamodb.GetItem: … with a response body of length 2 being b'{}'
azul.oauth2    Making GET request to 'https://www.googleapis.com/oauth2/v3/tokeninfo?access_token=…'
azul.oauth2    … with a response body of length 43 being b'{\n  "error_description": "Invalid Value"\n}\n'
azul.oauth2    Got 400 response after 0.149s from GET to https://www.googleapis.com/oauth2/v3/tokeninfo?access_token=…
azul.terra     Invalid credentials
                 Traceback (most recent call last):
                   File "/var/task/azul/service/source_service.py", line 193, in _get
                     result = response['Item']
                 KeyError: 'Item'
                 During handling of the above exception, another exception occurred:
                 …
azul.chalice   Returning 401 response with headers {…}
azul.chalice   … with a response body of length 63 being
                 {"Code": "UnauthorizedError", "Message": "Invalid credentials"}

Activity

  1. changed the title [-]No log message explains a 401 when[/-] [+]No log message explains the 401 when APAT is used with endpoint that doesn't support APAT yet[/+] on Oct 2, 2026
  2. changed the title [-]No log message explains the 401 when APAT is used with endpoint that doesn't support APAT yet[/-] [+]No log message explains the 401 when APAT is used with endpoint that doesn't support APATs yet[/+] on Oct 2, 2026
  3. added
    infra[subject] Project infrastructure like CI/CD, build and deployment scripts
    on Oct 5, 2026
  4. added theissue type on Oct 5, 2026
  5. self-assigned this
    on Oct 5, 2026
  6. changed the title [-]No log message explains the 401 when APAT is used with endpoint that doesn't support APATs yet[/-] [+]Controllers non supporting APATs should reject them outright[/+] on Oct 6, 2026
  7. changed the title [-]Controllers non supporting APATs should reject them outright[/-] [+]Controllers not supporting APATs should reject them outright[/+] on Oct 6, 2026
  8. changed the title [-]Controllers not supporting APATs should reject them outright[/-] [+]Controllers not supporting APATs don't reject them outright[/+] on Oct 6, 2026
  9. changed the title [-]Controllers not supporting APATs don't reject them outright[/-] [+]Controllers not supporting APATs don't reject them early[/+] on Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

infra[subject] Project infrastructure like CI/CD, build and deployment scripts

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions