fix(actions): return 401 for unregistered runner (#39578)

## Summary

When an Actions runner's registration has been deleted (or the
UUID/token is invalid), `FetchTask` and other authenticated runner RPCs
currently return **HTTP 500**


## Change

- Return `connect.NewError(connect.CodeUnauthenticated, ...)` via a
small `unregisteredRunnerError()` helper for both unregistered /
bad-token paths in the interceptor.
- Leave Internal `status.Error` paths unchanged (those should remain
5xx).
- Add a unit test asserting `connect.CodeOf(err) ==
connect.CodeUnauthenticated`.

Fixes #39576


---------

Signed-off-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: Alex Mitre <mitre88@users.noreply.github.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
authored and GitHub committed 2026-10-04 10:28:32 +00:00
1 parent a9ac8c0afd
commit 826c65d0ec
1 file changed
+5 -2
+5 -2
View File
@@ -27,6 +27,9 @@ const (
)
var withRunner = connect.WithInterceptors(connect.UnaryInterceptorFunc(func(unaryFunc connect.UnaryFunc) connect.UnaryFunc {
// A plain gRPC status.Error is treated as unknown by Connect and becomes HTTP 500
// To respond an HTTP status code, use connect.Error instead
errUnregisteredRunner := connect.NewError(connect.CodeUnauthenticated, errors.New("unregistered runner"))
return func(ctx context.Context, request connect.AnyRequest) (connect.AnyResponse, error) {
methodName := getMethodName(request)
if methodName == "Register" {
@@ -38,12 +41,12 @@ var withRunner = connect.WithInterceptors(connect.UnaryInterceptorFunc(func(unar
runner, err := actions_model.GetRunnerByUUID(ctx, uuid)
if err != nil {
if errors.Is(err, util.ErrNotExist) {
return nil, status.Error(codes.Unauthenticated, "unregistered runner")
return nil, errUnregisteredRunner
}
return nil, status.Error(codes.Internal, err.Error())
}
if !util.CryptoConstTimeEqual(runner.TokenHash, auth_model.HashToken(token, runner.TokenSalt)) {
return nil, status.Error(codes.Unauthenticated, "unregistered runner")
return nil, errUnregisteredRunner
}
now := time.Now()