oci-registry: Fix wrong token used in mirror_blob download

flatpak_oci_registry_mirror_blob uses self->token (destination registry)
instead of source_registry->token when downloading from the source. All
other parameters on the same call correctly use source_registry.

In practice the destination is always a local on-disk registry with no
token set, so this results in missing authentication when pulling from
authenticated source registries rather than a credential leak.
This commit is contained in:
Sebastian Wick committed 2026-08-04 11:38:22 +00:00
1 parent 660d3dfcfd
commit 56c40cc693
1 file changed
+1 -1
+1 -1
View File
@@ -1110,7 +1110,7 @@ flatpak_oci_registry_mirror_blob (FlatpakOciRegistry *self,
if (!flatpak_download_http_uri (source_registry->http_session,
uri_s, source_registry->certificates,
FLATPAK_HTTP_FLAGS_ACCEPT_OCI, out_stream,
self->token,
source_registry->token,
progress_cb, user_data,
cancellable, error))
return FALSE;