Skip to content

fix: use uppercase Bearer in Authorization headers - #123

Closed
SureneruS wants to merge 1 commit into
permitio:mainfrom
SureneruS:fix/bearer-case
Closed

SureneruS wants to merge 1 commit into
permitio:mainfrom
SureneruS:fix/bearer-case

Conversation

@SureneruS

Copy link
Copy Markdown
Contributor

Summary

The Cloud PDP requires uppercase "Bearer" in the Authorization header per RFC 6750. Using lowercase "bearer" causes 401 Unauthorized errors.

Changes

Fixed 4 files:

  • permit/enforcement/enforcer.py:47
  • permit/api/base.py:177
  • permit/pdp_api/base.py:51
  • permit/pdp_api/pdp_api_client.py:22

Testing

  • Verified 401 error with lowercase bearer
  • Verified success with uppercase Bearer

Fixes #122

The Cloud PDP requires uppercase "Bearer" in the Authorization header
per RFC 6750. Using lowercase "bearer" causes 401 Unauthorized errors.

Fixes permitio#122
@zeevmoney
zeevmoney requested a review from Copilot December 31, 2025 18:00

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes Authorization header formatting to comply with RFC 6750 by changing "bearer" to "Bearer" (uppercase). The Cloud PDP was rejecting requests with lowercase "bearer" and returning 401 Unauthorized errors.

  • Changed Authorization header format from f"bearer {token}" to f"Bearer {token}" across all API client implementations

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.

File Description
permit/pdp_api/pdp_api_client.py Updated Authorization header to use uppercase "Bearer" in PDP API client initialization
permit/pdp_api/base.py Updated Authorization header to use uppercase "Bearer" in HTTP client builder
permit/enforcement/enforcer.py Updated Authorization header to use uppercase "Bearer" in enforcer initialization
permit/api/base.py Updated Authorization header to use uppercase "Bearer" in API base HTTP client builder

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@zeevmoney zeevmoney left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the contribution!

@zeevmoney

Copy link
Copy Markdown
Member

Thanks @SureneruS, both for the report in #122 and for this fix. Your change is merged to main as part of #126, with you credited as co-author on the commit, and ships in permit 3.0.0.

The SDK now sends the canonical Authorization: Bearer <token> header everywhere it builds one (REST API client, PDP API client and enforcer), and a new offline test checks the header on the wire so it can't slip back to lowercase. On the server side, the Cloud PDP was updated the same day you reported this to accept lowercase bearer as well, so older SDK versions no longer get the 401 either.

Closing this as incorporated into #126. Thanks again!

@zeevmoney zeevmoney closed this Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cloud PDP returns 401 due to lowercase "bearer" in Authorization header

3 participants