Hello,

I'm trying to get this module to work now for quite some time after finding out that the services module doesn't provide what we needed.
But i keep getting 403 forbidden as a response on resources as nodes which are definitely accesible for unauthorized users. I even get a 403 on the login page for the simple_basic_auth module. As for nodes i have granted all users permissons to acces them also as a service.

I hope someone can shine a light on what i'm propably doing wrong.

Thanks in advance,
Tim

Comments

neograph734’s picture

To elaborate a bit more on this issue, we've figured that the services_basic_auth module was in fact working with the services module and provided no authentication for this module.

But the strange thing is that the token request url restws/session/token only works if the user is logged in (code below). So the question rises what step are we missing to log in the users remotely. And what about nodes that don't need authentication?

/**
 * Implements hook_menu().
 */
function restws_menu() {
  $items['restws/session/token'] = array(
    'page callback' => 'restws_session_token',
    // Only authenticated users are allowed to retrieve a session token.
    'access callback' => 'user_is_logged_in',
    'type' => MENU_CALLBACK,
  );
  return $items;
}
neograph734’s picture

Title: 403 on nodes and login url » Authentication headers not sent on certain server configarations
Version: 7.x-2.1 » 7.x-2.x-dev
Component: Miscellaneous » Code
Category: Support request » Bug report
Status: Active » Needs review
StatusFileSize
new1.7 KB

It turned out this issue was due to two things.

1. The authentication headers was always empty.
2. The 403 page was cached. (I'll open a second ticket for that).

Virtual Private Server:

OS: Centos 6.3
PHP: 5.3.27
Apache: 2.4.6
DirectAdmin: 1.44.0

I've attached a patch that worked for our configuration (and future PHP CGI versions as of PHP 5.4 http://www.php.net/manual/en/function.getallheaders.php)

klausi’s picture

Status: Needs review » Postponed (maintainer needs more info)

Did you try the instructions from the README file and the code comments?

Compatibility with Apache + PHP as CGI/FCGI:
--------------------------------------------

Unfortunately PHP_AUTH_USER & PHP_AUTH_PW server variables are not available
when PHP is run as CGI/FCGI under Apache. However, it is possible to make the
module work in such an environment by adding the following line to your
.htaccess file:

  RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
  1. +++ b/restws_basic_auth/restws_basic_auth.module
    @@ -11,14 +11,26 @@
    +    if (isset($headers['Authorization']) AND !empty($headers['Authorization'])) {
    

    we use "&&" instead of "AND" in Drupal.

  2. +++ b/restws_basic_auth/restws_basic_auth.module
    @@ -11,14 +11,26 @@
    +  ¶
    

    trailing white space.

neograph734’s picture

Hi klausi,

Thanks for the fast reply. I've tried that and could get it working with
RewriteRule .* - [E=HTTP_AUTHORIZATION:base64login] (Where base64login is my encoded credentials. But %{HTTP:Authorization} appeared to be always empty.

I've googled for this problem and ended up here: http://www.besthostratings.com/articles/http-auth-php-cgi.html where in the comments people state sometimes it is prefixed with REDIRECTED_. No success.

This is the only way I could get it working.

I'll get you a new patch.

neograph734’s picture

StatusFileSize
new1.69 KB

Added the patch

klausi’s picture

Status: Postponed (maintainer needs more info) » Needs work
  1. +++ b/restws_basic_auth/restws_basic_auth.module
    @@ -11,14 +11,26 @@
    +  // Try to get the headers via PHP
    +  if ($headers = getallheaders()) {
    +    if (isset($headers['Authorization']) && !empty($headers['Authorization'])) {
    +      $authentication = base64_decode(substr($headers['Authorization'], 6));
    +    }
    +  }
    ...
    +  elseif (!empty($_SERVER['REDIRECT_HTTP_AUTHORIZATION']) && !isset($_SERVER['PHP_AUTH_USER']) && !isset($_SERVER['PHP_AUTH_PW'])) {
    

    we should only invoke getallheaders() as a last resort and only if checking $_SERVER['PHP_AUTH_USER'] failed and $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] failed.

  2. +++ b/restws_basic_auth/restws_basic_auth.module
    @@ -11,14 +11,26 @@
    +  ¶
    

    trailing white spaces are still there.

neograph734’s picture

Oke, I've reversed the statement, checking for the second time if PHP_AUTH_USER and PHP_AUTH_PW aren't set already. Furthermore I've added a check for HTTP_AUTHORIZATION (without REDIRECT_) as that seems to happen as well (according to the url in #4).

I was assuming that getallheaders() was more generic and thus preferred, but it also generates more data.

I've checked for all trailing spaces, so if they are still there I blame it on TurtoiseGit.

neograph734’s picture

StatusFileSize
new1.81 KB
neograph734’s picture

Status: Needs work » Needs review

Forgot to update the status so testbot will pick it up.

The last submitted patch, 5: 2132653-Empty_Auth_Header-5.patch, failed testing.

klausi’s picture

Status: Needs review » Needs work
+++ b/restws_basic_auth/restws_basic_auth.module
@@ -15,10 +15,20 @@ function restws_basic_auth_init() {
-  if (!empty($_SERVER['REDIRECT_HTTP_AUTHORIZATION']) && !isset($_SERVER['PHP_AUTH_USER']) && !isset($_SERVER['PHP_AUTH_PW'])) {
...
+    $authentication = base64_decode(substr((!empty($_SERVER['HTTP_AUTHORIZATION']) ? $_SERVER['HTTP_AUTHORIZATION'] : $_SERVER['REDIRECT_HTTP_AUTHORIZATION']), 6));
...
+  // If that did not work, we attempt the fallback
+  elseif ($headers = getallheaders() && !isset($_SERVER['PHP_AUTH_USER']) && !isset($_SERVER['PHP_AUTH_PW'])) {
+    if (isset($headers['Authorization']) && !empty($headers['Authorization'])) {
+      $authentication = base64_decode(substr($headers['Authorization'], 6));
+    }
+  }

Now we are checking !isset($_SERVER['PHP_AUTH_USER']) twice? That should be handled in one if block.

neograph734’s picture

Issue summary: View changes
Status: Needs work » Needs review
StatusFileSize
new2.17 KB

I've improved it a bit, but I think it is better to check twice because blindly assuming that the username and password are set looks like bad practice.

klausi’s picture

Status: Needs review » Needs work

Well, you can just return and stop from further trying to authenticate the request if you cannot get any authentication header?

Status: Needs work » Needs review

lokapujya queued 12: 2132653-12.patch for re-testing.

Status: Needs review » Needs work

The last submitted patch, 12: 2132653-12.patch, failed testing.

lokapujya’s picture

Title: Authentication headers not sent on certain server configarations » Authentication headers not sent on certain server configurations