fix(auth): add Bearer prefix to PocketBase Authorization header

PocketBase v0.23+ requires 'Bearer <token>' — sending the raw JWT without
the prefix results in 403 'Only superusers can perform this action' on all
collection record endpoints. Fix applied in three places:
- ui/src/lib/server/pocketbase.ts (pbGet, pbPost, pbPatch helpers)
- scraper/internal/storage/pocketbase.go (pbClient.do)
- scripts/pb-init.sh (wget --header in create_collection)
This commit is contained in:
Admin
2026-03-03 20:15:44 +05:00
parent a0344b36d7
commit d89cefe975
3 changed files with 5 additions and 5 deletions

View File

@@ -119,7 +119,7 @@ func (p *pbClient) do(ctx context.Context, method, path string, body interface{}
if err != nil { if err != nil {
return nil, err return nil, err
} }
req.Header.Set("Authorization", tok) req.Header.Set("Authorization", "Bearer "+tok)
if body != nil { if body != nil {
req.Header.Set("Content-Type", "application/json") req.Header.Set("Content-Type", "application/json")
} }

View File

@@ -44,7 +44,7 @@ create_collection() {
BODY="$2" BODY="$2"
STATUS=$(wget -qSO- \ STATUS=$(wget -qSO- \
--header="Content-Type: application/json" \ --header="Content-Type: application/json" \
--header="Authorization: $TOKEN" \ --header="Authorization: Bearer $TOKEN" \
--post-data="$BODY" \ --post-data="$BODY" \
"$PB_URL/api/collections" 2>&1 | grep "HTTP/" | tail -1 | awk '{print $2}') "$PB_URL/api/collections" 2>&1 | grep "HTTP/" | tail -1 | awk '{print $2}')
case "$STATUS" in case "$STATUS" in

View File

@@ -85,7 +85,7 @@ async function getToken(): Promise<string> {
async function pbGet<T>(path: string): Promise<T> { async function pbGet<T>(path: string): Promise<T> {
const token = await getToken(); const token = await getToken();
const res = await fetch(`${PB_URL}${path}`, { const res = await fetch(`${PB_URL}${path}`, {
headers: { Authorization: token } headers: { Authorization: `Bearer ${token}` }
}); });
if (!res.ok) { if (!res.ok) {
const body = await res.text().catch(() => ''); const body = await res.text().catch(() => '');
@@ -99,7 +99,7 @@ async function pbPost(path: string, body: unknown): Promise<Response> {
const token = await getToken(); const token = await getToken();
return fetch(`${PB_URL}${path}`, { return fetch(`${PB_URL}${path}`, {
method: 'POST', method: 'POST',
headers: { Authorization: token, 'Content-Type': 'application/json' }, headers: { Authorization: `Bearer ${token}`, 'Content-Type': 'application/json' },
body: JSON.stringify(body) body: JSON.stringify(body)
}); });
} }
@@ -108,7 +108,7 @@ async function pbPatch(path: string, body: unknown): Promise<Response> {
const token = await getToken(); const token = await getToken();
return fetch(`${PB_URL}${path}`, { return fetch(`${PB_URL}${path}`, {
method: 'PATCH', method: 'PATCH',
headers: { Authorization: token, 'Content-Type': 'application/json' }, headers: { Authorization: `Bearer ${token}`, 'Content-Type': 'application/json' },
body: JSON.stringify(body) body: JSON.stringify(body)
}); });
} }