Where: src/token.rs:9-17 (extract_bearer).
h.strip_prefix("Bearer ") is case-sensitive, so bearer <token> or BEARER <token> (both valid per common client behavior / not forbidden by RFC 6750 in a case-insensitive sense for the scheme name) fail to extract a token and the request is rejected as unauthenticated, even with an otherwise valid JWT. Minor correctness/interop issue, low severity.
Fix direction: match the Bearer scheme name case-insensitively while keeping the token itself untouched.
Where:
src/token.rs:9-17(extract_bearer).h.strip_prefix("Bearer ")is case-sensitive, sobearer <token>orBEARER <token>(both valid per common client behavior / not forbidden by RFC 6750 in a case-insensitive sense for the scheme name) fail to extract a token and the request is rejected as unauthenticated, even with an otherwise valid JWT. Minor correctness/interop issue, low severity.Fix direction: match the
Bearerscheme name case-insensitively while keeping the token itself untouched.