Release 2.16 (#4780)
This commit is contained in:
@@ -27,7 +27,8 @@ final class ApiRequestMatcher implements RequestMatcherInterface
|
||||
}
|
||||
|
||||
// let's use this firewall if a Bearer token is set in the header
|
||||
if ($request->headers->has('Authorization')) {
|
||||
// other cases like "bearer" are rejected earlier
|
||||
if (($auth = $request->headers->get('Authorization')) !== null && str_starts_with($auth, 'Bearer ')) {
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
@@ -232,7 +232,7 @@ final class UserController extends BaseApiController
|
||||
throw $this->createAccessDeniedException('User has no access to API tokens');
|
||||
}
|
||||
|
||||
if ($accessToken->getUser() !== $user) {
|
||||
if (!$this->isGranted('api-token', $accessToken->getUser())) {
|
||||
throw $this->createAccessDeniedException('You are not allowed to delete this access token');
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user