(w http.ResponseWriter, r *http.Request)
| 94 | } |
| 95 | |
| 96 | func checkToken(w http.ResponseWriter, r *http.Request) (bool, string) { |
| 97 | auth := r.Header.Get("authorization") |
| 98 | if auth == "" { |
| 99 | http.Error(w, "auth header missing", http.StatusUnauthorized) |
| 100 | return false, "" |
| 101 | } |
| 102 | if !strings.HasPrefix(auth, oidc.PrefixBearer) { |
| 103 | http.Error(w, "invalid header", http.StatusUnauthorized) |
| 104 | return false, "" |
| 105 | } |
| 106 | return true, strings.TrimPrefix(auth, oidc.PrefixBearer) |
| 107 | } |