Problem/Motivation
When Drupal is configured with URL language negotiation or country/language prefix paths (e.g. /en/user/login, /int/en/user/login), the
RestAPI::authenticate()
method does not correctly bypass authentication for the user login endpoint.
The current bypass check inside authenticate():
if ($request->getPathInfo() === '/user/login') {
return NULL;
}
fails for any prefixed path because getPathInfo() returns the full path including the language prefix.
Impact: Users cannot log in via the standard Drupal login endpoint when language negotiation adds a prefix to URLs.
Steps to reproduce
- Enable URL language negotiation with a prefix (e.g. /en/).
- Make a curl POST to /en/user/login?_format=json with valid credentials.
- Observe the request is rejected with a 400/401 instead of authenticating.
Expected: Login succeeds as it does on /user/login.
Actual: Authentication provider intercepts and rejects the request.
Proposed resolution
- Use
str_ends_with()instead of strict equality to match prefixed paths.
Remaining tasks
User interface changes
None
API changes
RestApi.php
Data model changes
Issue fork rest_api_authentication-3611160
Show commands
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
mohammad-fayoumiComment #4
nitinkumar_7 commentedTested locally with URL language negotiation enabled (/en/, /fr/, /int/en/ prefixes).
Before the patch: /en/user/login gets rejected with a error code 40
After applying MR !8: login succeeds on all prefixed paths I tried, and plain /user/login still works too