Problem/Motivation
It is frustrating to define API-first routes if you do not care which authentication method is used since it can only be done programmatically. This is because the route developer can't know which methods the site builder has enabled (e.g. basic_auth) in advance, but every authentication method must be explicitly specified.
See an example in core.
See an example in contrib.
Proposed resolution
Allow routes to be defined with _auth: 'TRUE' to permit any available authentication method.
Alternative
If _auth is not defined, allow all methods instead of the default method. This would make it easier to define routes, but may break existing expectations.
API changes
Additional allowed value in a route definitions.
Data model changes
None.
Release notes snippet
Routes can now be defined to permit all enabled authentication methods without writing custom code by specifying
_auth: 'TRUE'in their route definitions.
Comments
Comment #2
gabesulliceClarified the IS a bit.
Comment #3
gabesulliceWhile trying enable the default REST resource for nodes, I was frustrated because I could not simply visit
localhost/node/1?_format=hal_jsonafter enabling HAL + REST. It took me a couple minutes to realize that I was getting a403 Forbiddenbecause the system didn't like my cookie (I was logged in as uid 1). If I did not have lots of experience with these things, I expect this would have taken me a lot longer. I suspect the reason that REST configuration only enablesbasic_authout of the box is really a consequence of this issue.It seems like, in general, authentication methods should be a sitewide configuration, not a per-route configuration. This makes me think that the alternative solution is preferable:
We could add a BC flag to keep the old behavior for existing sites, but the above seems like a nice DX improvement to make.
Comment #4
wim leersI think the original thinking behind making this per-route for "REST resources" is to have fine-grained control over security implications.
It reminds me of what we were required to do in #3039568: Add a read-only mode to JSON:API for security considerations.
Comment #10
aubjr_drupal commentedThanks, @gabesullice for https://www.drupal.org/project/drupal/issues/3200620#comment-14040318.