fix(plugins/key-auth): only clear key from enabled sources #14800
+6
−2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Even if config.key_in_query is set to false, the query is still modified by the cleanup code. i.e. "%20" will be replaced by "+" for any query parameter. This maybe surprising to the user, as the config option was explicitly disabled.
For key_in_body this is already handled differently. I.e. body is only modified if key_in_body is true.
To make the cleanup code behave more consistent and expectable this PR makes the cleanup also conditional for query and header.
Checklist
changelog/unreleased/kongorskip-changeloglabel added on PR if changelog is unnecessary. README.mdIssue reference