From 83cee29ff715b5278f1e8be7c7a05c19d8b31fa6 Mon Sep 17 00:00:00 2001 From: James Hodgkinson Date: Sat, 20 Jun 2026 22:12:30 +1000 Subject: [PATCH] fix(dashboard): set headers for JWKS requests --- .../dashboard_auth/self_hosted/__init__.py | 4 ++++ .../test_self_hosted_provider.py | 20 +++++++++++++++++++ 2 files changed, 24 insertions(+) diff --git a/plugins/dashboard_auth/self_hosted/__init__.py b/plugins/dashboard_auth/self_hosted/__init__.py index fe01cb97232..2672006571c 100644 --- a/plugins/dashboard_auth/self_hosted/__init__.py +++ b/plugins/dashboard_auth/self_hosted/__init__.py @@ -601,6 +601,10 @@ class SelfHostedOIDCProvider(DashboardAuthProvider): disco["jwks_uri"], cache_keys=True, lifespan=_JWKS_CACHE_SECONDS, + headers={ + "Accept": "application/json", + "User-Agent": "HermesAgent/1.0", + }, ) return self._jwks_client diff --git a/tests/plugins/dashboard_auth/test_self_hosted_provider.py b/tests/plugins/dashboard_auth/test_self_hosted_provider.py index a83988ce932..fcd767279e3 100644 --- a/tests/plugins/dashboard_auth/test_self_hosted_provider.py +++ b/tests/plugins/dashboard_auth/test_self_hosted_provider.py @@ -571,6 +571,26 @@ class TestVerifySession: with pytest.raises(ProviderError, match="JWKS"): provider.verify_session(access_token=token) + def test_jwks_client_sends_explicit_http_headers(self): + provider = oidc_plugin.SelfHostedOIDCProvider( + issuer=_ISSUER, client_id=_CLIENT_ID + ) + provider._discovery = dict(_DISCOVERY_DOC) + provider._discovery_fetched_at = time.time() + + with patch("jwt.PyJWKClient") as client_cls: + provider._get_jwks_client() + + client_cls.assert_called_once_with( + _DISCOVERY_DOC["jwks_uri"], + cache_keys=True, + lifespan=oidc_plugin._JWKS_CACHE_SECONDS, + headers={ + "Accept": "application/json", + "User-Agent": "HermesAgent/1.0", + }, + ) + # --------------------------------------------------------------------------- # refresh_session + revoke_session