Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Surprises never stop coming. This refactors the OCI engine to follow Docker's authentication dance per the distribution registry spec. Essentially, even if registry credentials are added via
docker login oci.pkg.keygen.sh
, Docker won't send the credentials unless the registry first sends a 401 Unauthorized status code (imo a waste of time and bandwidth but wtfe).The downside to this is that we now leak information by responding with 401/403s instead of 404s, but since this is limited only to packages using an OCI engine, I think the risk is low and it can be considered expected behavior.
Follow up to #914.