Azure / Azure/data-api-builder
DAB returns 500 on failed authorization
- Dominant language
- C#
- Stars
- 1.5k
- Forks
- 370
- Avg merge
- 3d 17h
- Merged PRs (30d)
- 8
Description
Sending a request that should result in a 401/403 ends up with a 500 + a message that says that the user is unauthorized.

Config:
```json
{
"$schema": "../schemas/hawaii.draft-01.schema.json",
"data-source": {
"connection-string": "AccountEndpoint=https://hawaii-demo.documents.azure.com:443/;",
"database-type": "cosmosdb_nosql",
"options": {
"database": "mydb",
"container": "joslin2",
"schema": "schema.gql"
}
},
"runtime": {
"rest": {
"enabled": false
},
"graphql": {
"enabled": true,
"path": "/graphql",
"allow-introspection": true
},
"host": {
"mode": "development",
"cors": {
"origins": [
"http://localhost:5000"
],
"allow-credentials": false
},
"authentication": {
"provider": "StaticWebApps"
}
}
},
"entities": {
"Player": {
"source": "mydb.joslin2",
"rest": false,
"graphql": true,
"permissions": [
{
"role": "anonymous",
"actions": [
]
},
{
"role": "authenticated",
"actions": [
"read"
]
},
{
"role": "contributor",
"actions": [
"create",
"read",
"update",
"delete"
]
}
]
}
}
}
```
Schema:
```gql
type Player @model {
id : ID,
name : String,
played: Int,
winPercent: Float,
currentStreak: Int,
maxStreak: Int
}
```
Contributor guide
Assessment
This issue has not been assessed yet.