Skip to content

Send the Authorization header only when PEERINGDB_API_KEY is set - #2

Merged
digizeph merged 1 commit into
bgpkit:mainfrom
hellerve:fix-empty-auth-header
Aug 10, 2026
Merged

digizeph merged 1 commit into
bgpkit:mainfrom
hellerve:fix-empty-auth-header

Conversation

@hellerve

Copy link
Copy Markdown
Contributor

When PEERINGDB_API_KEY is unset, get_reader sends Authorization: Api-Key with an empty key, which PeeringDB rejects with HTTP 400 {"error": "Unknown authorization method"}.

This means that keyless calls currently always fail. Omitting the header entirely makes anonymous requests work (subject to anonymous rate limits). The existing warning is kept.

Cheers

@digizeph digizeph left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review (via Hermes Agent)

Verified the bug and the fix against the live API: with the old code the empty Authorization: Api-Key header gets a hard 400 Bad Request from PeeringDB; with the header omitted (this PR) the API answers and only rate-limits (429) without a key, as the warning says. The Ok(key) if !key.is_empty() guard also handles an empty env var. fmt/clippy clean locally, CI build passed. LGTM.

Note: PR #3 branched from pre-fix main still contains the unconditional empty auth header in its get_reader_with_params refactor — rebase it on this to avoid reverting the fix.

@digizeph
digizeph merged commit 6eabf3c into bgpkit:main Aug 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants