Skip to content

Guard authenticate() entry point against exceptions - #11

Merged
villagesql-adam merged 1 commit into
mainfrom
auto/adopt-exception-guards
Sep 17, 2026
Merged

villagesql-adam merged 1 commit into
mainfrom
auto/adopt-exception-guards

Conversation

@villagesql-adam

@villagesql-adam villagesql-adam commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

Adds missing exception handling.
AI=CLAUDE

authenticate() itself (renamed authenticate_impl) had no try/catch
around its own body, even though the JWT-parsing/signature-verification/
regex/JWKS-JSON helpers it calls (evaluate(), map_roles(), JwksCache)
already guard themselves. The uncaught paths were in authenticate()'s
own body: std::string construction from the raw handshake packet,
build_config()/build_key_resolver()'s std::function/std::string copies,
and the two std::vector<const char*> role-pointer buffers -- all can
throw std::bad_alloc under memory pressure. VEF does not catch
exceptions at the preview/auth entry-point boundary, so an escaping
exception here crashes the whole server rather than just failing the
one login.

Added a thin authenticate() wrapper around authenticate_impl that fails
closed (AuthResult::kError) on any exception, consistent with every
other rejection path already in this function.

AI=CLAUDE
Co-Authored-By: Claude <claude-opus-4-6@noreply.anthropic.com>
@villagesql-adam villagesql-adam self-assigned this Sep 15, 2026
@villagesql-adam
villagesql-adam marked this pull request as ready for review September 16, 2026 17:30
@villagesql-adam
villagesql-adam merged commit 5aea9d0 into main Sep 17, 2026
5 of 6 checks passed
@villagesql-adam
villagesql-adam deleted the auto/adopt-exception-guards branch September 17, 2026 14:28
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 17, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants