Repository navigation
Conversation
GetDefaultSession already loads the default profile to find the account entry, but threw it away. Since the token's username claim is often empty, callers had to call GetDefaultProfile again to get a username for a registry credential. Add UserSession.Username. GetDefaultSession fills it from the default profile, falling back to the username claim; GetSession fills it from the requested username. The field is not decoded from the stored payload. Refs #682 Signed-off-by: Alano Terblanche <18033717+Benehiko@users.noreply.github.com>
Benehiko
marked this pull request as ready for review
October 9, 2026 05:28
Signed-off-by: Alano Terblanche <18033717+Benehiko@users.noreply.github.com>
docker-agent
reviewed
Oct 9, 2026
docker-agent
left a comment
Contributor
There was a problem hiding this comment.
Assessment: 🟢 APPROVE
Benehiko
marked this pull request as draft
October 9, 2026 06:05
Member
Author
|
Closing: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #682 (item 1).
GetDefaultSessionalready reads the default profile to find the account entry, but it threw the profile away.UserSession.Claims.Usernameis often empty. That forces callers such as Compose to callGetDefaultProfilea second time to get the username a registry credential needs.This adds
UserSession.Username:GetDefaultSessionsets it to the default profile's username, or to the token'susernameclaim if the profile has none.GetSessionsets it to the requested username, which is the account entry key (docker/auth/hub/<username>).The field is tagged
json:"-"because the client fills it in; it is not read from the stored payload. Adding a struct field doesn't break callers, and theClientAuthinterface is unchanged. On the Compose side, the profile fallback becomessession.Username.Details
Open questions
GetDefaultSessionstill succeeds withUsername == "", so callers that only need the token keep working. Two other options are left out for now: fall back to the last part of the profile'suser_id(the account key), or return an error.Out of scope: items 2–5 of #682 (expiry helper,
ErrSessionExpired, an "unavailable" check, connecting to the Desktop socket). These can be separate PRs.Testing:
go test -race ./...andgolangci-lint runinclient/(0 issues). New subtests cover each username source, the precedence, the empty case, and a top-levelusernamein the stored payload being ignored. One test checks thatGetDefaultSessiondoes exactly one profile lookup and one session lookup.AI usage: The code, tests and this description were drafted with alki, a coding agent built on Claude.