Problem/Motivation

When Drupal is configured with URL language negotiation or country/language prefix paths (e.g. /en/user/login, /int/en/user/login), the

RestAPI::authenticate()

method does not correctly bypass authentication for the user login endpoint.

The current bypass check inside authenticate():

if ($request->getPathInfo() === '/user/login') {
    return NULL;
}

fails for any prefixed path because getPathInfo() returns the full path including the language prefix.

Impact: Users cannot log in via the standard Drupal login endpoint when language negotiation adds a prefix to URLs.

Steps to reproduce

  1. Enable URL language negotiation with a prefix (e.g. /en/).
  2. Make a curl POST to /en/user/login?_format=json with valid credentials.
  3. Observe the request is rejected with a 400/401 instead of authenticating.

Expected: Login succeeds as it does on /user/login.
Actual: Authentication provider intercepts and rejects the request.

Proposed resolution

  • Use str_ends_with() instead of strict equality to match prefixed paths.

Remaining tasks

User interface changes

None

API changes

RestApi.php

Data model changes

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

mohammad-fayoumi created an issue. See original summary.

mohammad-fayoumi’s picture

Status: Active » Needs review
nitinkumar_7’s picture

Status: Needs review » Reviewed & tested by the community

Tested locally with URL language negotiation enabled (/en/, /fr/, /int/en/ prefixes).
Before the patch: /en/user/login gets rejected with a error code 40
After applying MR !8: login succeeds on all prefixed paths I tried, and plain /user/login still works too