fix(caddy): strip empty Bearer header on roms so RomM stops 500ing decky-romm-sync
Deploy to valhalla / deploy (push) Has been cancelled

RomM 4.8.x crashes with HTTP 500 on a malformed Authorization header:
hybrid_auth.py unpacks `scheme, token = header.split()` with no guard, so
any value without exactly two space-separated parts raises ValueError.

decky-romm-sync >=0.20.0 (Client API Token auth, added 2026-06-05) sends
`Authorization: Bearer ` with an empty token on its first-run heartbeat/
platforms/devices probes, before it has minted a token, which trips that
crash and deadlocks setup. The Basic-auth mint (POST /api/client-tokens)
is never reached.

Strip the empty-token header for the roms host so the probe gets a clean
200 and the mint can run; thereafter the plugin sends a real Bearer rmm_
token. Well-formed Bearer tokens and browser session-cookie auth are
unaffected. Remove once the plugin omits the empty header or RomM guards
the split.
This commit is contained in:
ginnoir
2026-06-06 16:00:25 -05:00
parent 7ec4e2ca57
commit a96ff619a8
+19 -1
View File
@@ -120,7 +120,25 @@ stash.ginnoir.com {
# GAMES / ROMS — public (temporarily; RomM has its own auth) # GAMES / ROMS — public (temporarily; RomM has its own auth)
# ============================================================= # =============================================================
roms.ginnoir.com { roms.ginnoir.com {
reverse_proxy romm:8080 # WORKAROUND (2026-06-06): RomM 4.8.x 500s on a malformed Authorization
# header — hybrid_auth.py does `scheme, token = header.split()` with no
# guard, so a value with !=2 space-separated parts raises ValueError.
# decky-romm-sync >=0.20.0 sends `Authorization: Bearer ` (empty token) on
# its first-run probes, before it has minted a Client API Token, which trips
# that crash and deadlocks setup (heartbeat/platforms/devices all 500).
# Strip the empty-token header so the heartbeat probe returns 200 and the
# Basic-auth token mint (POST /api/client-tokens) can run. Real `Bearer
# rmm_…` tokens and browser session-cookie auth are unaffected. Remove once
# the plugin omits the empty header (or RomM guards the split).
@romm_empty_bearer header_regexp Authorization "^Bearer\s*$"
handle @romm_empty_bearer {
reverse_proxy romm:8080 {
header_up -Authorization
}
}
handle {
reverse_proxy romm:8080
}
} }
# ============================================================= # =============================================================