fix(11-06): send Cache-Control: no-cache, private on the jwt.auth 401

The recorded PHP 401 for a missing bearer (realtime token no-bearer
case) carries Laravel's default Cache-Control header; the Go guard's
401 omitted it, so the replay failed on header.Cache-Control.
This commit is contained in:
Jakub Zych
2026-09-30 13:31:55 +02:00
parent 9ecbf74a22
commit 5382947ef8
3 changed files with 7 additions and 1 deletions

View File

@@ -366,6 +366,9 @@ func mapJWTError(err error) error {
func write401(w http.ResponseWriter, message string) {
w.Header().Set("Content-Type", "application/json")
// The reference backend (Laravel) sends this on every response, and a
// replayed 401 compares it.
w.Header().Set("Cache-Control", "no-cache, private")
w.WriteHeader(http.StatusUnauthorized)
_ = json.NewEncoder(w).Encode(map[string]any{"error": true, "message": message})
}