Needs work
Project:
RESTful Web Services
Version:
7.x-2.x-dev
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
10 Nov 2013 at 15:47 UTC
Updated:
31 Mar 2016 at 14:42 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #1
neograph734To elaborate a bit more on this issue, we've figured that the services_basic_auth module was in fact working with the services module and provided no authentication for this module.
But the strange thing is that the token request url
restws/session/tokenonly works if the user is logged in (code below). So the question rises what step are we missing to log in the users remotely. And what about nodes that don't need authentication?Comment #2
neograph734It turned out this issue was due to two things.
1. The authentication headers was always empty.
2. The 403 page was cached. (I'll open a second ticket for that).
Virtual Private Server:
OS: Centos 6.3
PHP: 5.3.27
Apache: 2.4.6
DirectAdmin: 1.44.0
I've attached a patch that worked for our configuration (and future PHP CGI versions as of PHP 5.4 http://www.php.net/manual/en/function.getallheaders.php)
Comment #3
klausiDid you try the instructions from the README file and the code comments?
we use "&&" instead of "AND" in Drupal.
trailing white space.
Comment #4
neograph734Hi klausi,
Thanks for the fast reply. I've tried that and could get it working with
RewriteRule .* - [E=HTTP_AUTHORIZATION:base64login](Where base64login is my encoded credentials. But%{HTTP:Authorization}appeared to be always empty.I've googled for this problem and ended up here: http://www.besthostratings.com/articles/http-auth-php-cgi.html where in the comments people state sometimes it is prefixed with
REDIRECTED_. No success.This is the only way I could get it working.
I'll get you a new patch.
Comment #5
neograph734Added the patch
Comment #6
klausiwe should only invoke getallheaders() as a last resort and only if checking $_SERVER['PHP_AUTH_USER'] failed and $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] failed.
trailing white spaces are still there.
Comment #7
neograph734Oke, I've reversed the statement, checking for the second time if
PHP_AUTH_USERandPHP_AUTH_PWaren't set already. Furthermore I've added a check for HTTP_AUTHORIZATION (without REDIRECT_) as that seems to happen as well (according to the url in #4).I was assuming that getallheaders() was more generic and thus preferred, but it also generates more data.
I've checked for all trailing spaces, so if they are still there I blame it on TurtoiseGit.
Comment #8
neograph734Comment #9
neograph734Forgot to update the status so testbot will pick it up.
Comment #11
klausiNow we are checking !isset($_SERVER['PHP_AUTH_USER']) twice? That should be handled in one if block.
Comment #12
neograph734I've improved it a bit, but I think it is better to check twice because blindly assuming that the username and password are set looks like bad practice.
Comment #13
klausiWell, you can just return and stop from further trying to authenticate the request if you cannot get any authentication header?
Comment #16
lokapujya