Release 2.17 (#4836)

see https://github.com/kimai/kimai/pull/4836
This commit is contained in:
Kevin Papst
2024-05-19 17:42:03 +02:00
committed by GitHub
parent 5f7114e008
commit 0c445d1bc4
41 changed files with 318 additions and 307 deletions

View File

@@ -16,30 +16,19 @@ final class ApiRequestMatcher implements RequestMatcherInterface
{
public function matches(Request $request): bool
{
// we do not want to handle URLs that
// we do not want to handle URLs that are not in the API scope
if (!str_starts_with($request->getRequestUri(), '/api/')) {
return false;
}
// API documentation is only available to registered users
// API documentation is only available to registered and logged-in users
if (str_starts_with($request->getRequestUri(), '/api/doc')) {
return false;
}
// let's use this firewall if a Bearer token is set in the header
// other cases like "bearer" are rejected earlier
if (($auth = $request->headers->get('Authorization')) !== null && str_starts_with($auth, 'Bearer ')) {
return true;
}
// let's use this firewall if the deprecated username & token combination is available
if ($request->headers->has(TokenAuthenticator::HEADER_USERNAME) &&
$request->headers->has(TokenAuthenticator::HEADER_TOKEN)) {
return true;
}
// checking for a previous session allows us to skip the API firewall and token access handler
// we simply re-use the existing session when doing API calls from the frontend
// we simply re-use the existing session when doing API calls from the frontend.
// it is not necessary to check headers. if there is no valid session, we should always use this firewall
return !$request->hasPreviousSession();
}
}