Skip to content

Bug 1202436 - Document authentication method precedence - #2722

Merged
dklawren merged 1 commit into
mozilla:masterfrom
loganrosen:loganrosen-fix-bugzilla-1202436
Aug 25, 2026
Merged

Bug 1202436 - Document authentication method precedence#2722
dklawren merged 1 commit into
mozilla:masterfrom
loganrosen:loganrosen-fix-bugzilla-1202436

Conversation

@loganrosen

Copy link
Copy Markdown
Contributor

Bug 1202436 tracks missing REST API documentation for requests that provide more than one authentication method. BMO evaluates legacy username/password credentials before API keys, so a valid API key can be ignored. When the account requires API-key authentication, the mixed request fails with an API key authentication is required error.

This documents the precedence, lack of fallback, and interaction with the Require API key authentication for API requests preference. It advises clients to send only the X-BUGZILLA-API-KEY header rather than disabling the preference. Authentication behavior is unchanged.

Bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1202436

Testing:

  • Built the Sphinx HTML documentation with the pinned requirements. The build succeeded with six pre-existing warnings.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings August 22, 2026 23:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documents BMO REST API authentication precedence and prevents client confusion when multiple credential types are supplied.

Changes:

  • Clarifies that username/password credentials take precedence over API keys without fallback.
  • Explains interaction with API-key-only accounts and recommends sending only the API key.
Show a summary per file
File Description
docs/en/rst/api/core/v1/general.rst Documents authentication precedence and remediation guidance.

Review details

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Balanced

@dklawren dklawren left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM r=dkl

@dklawren
dklawren merged commit 94a4e59 into mozilla:master Aug 25, 2026
8 checks passed
@loganrosen
loganrosen deleted the loganrosen-fix-bugzilla-1202436 branch August 25, 2026 02:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants