From 56c40cc6933d4c0be3daa5205f6aff2d3f835b5c Mon Sep 17 00:00:00 2001 From: Sebastian Wick Date: Thu, 2 Jul 2026 19:39:56 +0200 Subject: [PATCH] oci-registry: Fix wrong token used in mirror_blob download flatpak_oci_registry_mirror_blob uses self->token (destination registry) instead of source_registry->token when downloading from the source. All other parameters on the same call correctly use source_registry. In practice the destination is always a local on-disk registry with no token set, so this results in missing authentication when pulling from authenticated source registries rather than a credential leak. --- common/flatpak-oci-registry.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/common/flatpak-oci-registry.c b/common/flatpak-oci-registry.c index 6380b9ffa..4b314719d 100644 --- a/common/flatpak-oci-registry.c +++ b/common/flatpak-oci-registry.c @@ -1110,7 +1110,7 @@ flatpak_oci_registry_mirror_blob (FlatpakOciRegistry *self, if (!flatpak_download_http_uri (source_registry->http_session, uri_s, source_registry->certificates, FLATPAK_HTTP_FLAGS_ACCEPT_OCI, out_stream, - self->token, + source_registry->token, progress_cb, user_data, cancellable, error)) return FALSE;