feat: bearer auth for netbox 4.5 v2 api tokens

v2 tokens (nbt_<key>.<secret>) are sent as Authorization: Bearer, legacy
tokens keep the Token scheme; NetBox drops legacy token support in 4.7.
This commit is contained in:
2026-08-25 13:47:18 +02:00
parent 4195e7c3c3
commit e4a1e6a472
2 changed files with 21 additions and 1 deletions

View File

@@ -66,6 +66,18 @@ def _extract_error_message(response: requests.Response) -> str:
return f"NetBox API error: HTTP {response.status_code}" return f"NetBox API error: HTTP {response.status_code}"
def auth_header(token: str) -> str:
"""
Build the Authorization header value for a NetBox API token.
Version 2 tokens (NetBox 4.5+, "nbt_<key>.<secret>") use the Bearer
scheme, legacy tokens the Token scheme.
"""
if token.startswith("nbt_"):
return f"Bearer {token}"
return f"Token {token}"
class NetBoxClient: class NetBoxClient:
"""Thin wrapper around the NetBox REST API.""" """Thin wrapper around the NetBox REST API."""
@@ -76,7 +88,7 @@ class NetBoxClient:
self._session.verify = verify_ssl self._session.verify = verify_ssl
self._session.headers.update( self._session.headers.update(
{ {
"Authorization": f"Token {token}", "Authorization": auth_header(token),
"Accept": "application/json", "Accept": "application/json",
} }
) )

View File

@@ -16,6 +16,14 @@ def make_client() -> inv.NetBoxClient:
return inv.NetBoxClient(NETBOX_URL, "token", verify_ssl=True, timeout=5) return inv.NetBoxClient(NETBOX_URL, "token", verify_ssl=True, timeout=5)
class TestAuthHeader:
def test_legacy_token_uses_token_scheme(self):
assert inv.auth_header("0123456789abcdef") == "Token 0123456789abcdef"
def test_v2_token_uses_bearer_scheme(self):
assert inv.auth_header("nbt_abc.def") == "Bearer nbt_abc.def"
class TestStripPrefix: class TestStripPrefix:
def test_strips_prefix_length(self): def test_strips_prefix_length(self):
assert inv.strip_prefix("192.0.2.10/24") == "192.0.2.10" assert inv.strip_prefix("192.0.2.10/24") == "192.0.2.10"