diff --git a/routstr/payment/helpers.py b/routstr/payment/helpers.py index 4aea50c8..e0e9f337 100644 --- a/routstr/payment/helpers.py +++ b/routstr/payment/helpers.py @@ -29,7 +29,8 @@ def check_token_balance(headers: dict, body: dict, max_cost_for_model: int) -> N }, ) elif auth := headers.get("authorization", None): - cashu_token = auth.split(" ")[1] if len(auth.split(" ")) > 1 else "" + parts = auth.split() + cashu_token = parts[1] if len(parts) > 1 else "" logger.debug( "Using Authorization header token", extra={ diff --git a/routstr/proxy.py b/routstr/proxy.py index 7f72ff75..4d8f666d 100644 --- a/routstr/proxy.py +++ b/routstr/proxy.py @@ -390,7 +390,8 @@ async def get_bearer_token_key( headers: dict, path: str, session: AsyncSession, auth: str, min_cost: int = 0 ) -> ApiKey: """Handle bearer token authentication proxy requests.""" - bearer_key = auth.replace("Bearer ", "") if auth.startswith("Bearer ") else "" + parts = auth.split() + bearer_key = parts[1] if len(parts) > 1 and parts[0].lower() == "bearer" else "" refund_address = headers.get("Refund-LNURL", None) key_expiry_time = headers.get("Key-Expiry-Time", None)