add basic authentication with user, password and api key
This commit is contained in:
@@ -0,0 +1,5 @@
|
|||||||
|
@term=MA
|
||||||
|
|
||||||
|
GET http://localhost:8000/api/dipendenti/cerca?term={{term}}
|
||||||
|
Authorization: Basic elixforms_ws:password123
|
||||||
|
X-API-Key: myApiAccessToken
|
||||||
+1
-1
@@ -82,7 +82,7 @@ if (strpos($request->path(), '/api/') === 0) {
|
|||||||
$authenticator->authenticate($request);
|
$authenticator->authenticate($request);
|
||||||
} catch (\Throwable $e) {
|
} catch (\Throwable $e) {
|
||||||
$logger->warning('External API auth failed', ['path' => $request->path(), 'error' => $e->getMessage()]);
|
$logger->warning('External API auth failed', ['path' => $request->path(), 'error' => $e->getMessage()]);
|
||||||
$response->json(['error' => 'Unauthorized'], 401);
|
$response->unauthorized();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -15,20 +15,32 @@ class ApiTokenAuthenticator
|
|||||||
|
|
||||||
public function authenticate(Request $request): void
|
public function authenticate(Request $request): void
|
||||||
{
|
{
|
||||||
$authorization = $_SERVER['HTTP_AUTHORIZATION'] ?? $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] ?? '';
|
$authorizationHeader = $_SERVER['HTTP_AUTHORIZATION'] ?? $_SERVER['REDIRECT_HTTP_AUTHORIZATION'] ?? '';
|
||||||
if (!$authorization) {
|
if (!$authorizationHeader) {
|
||||||
throw new \Exception('Missing Authorization header');
|
throw new \Exception('Missing Authorization header');
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!preg_match('/^Bearer\s+(.*)$/i', trim($authorization), $matches)) {
|
// Basic authorization formal test
|
||||||
|
if (!preg_match('/^Basic\s+(.*)$/i', trim($authorizationHeader), $matches)) {
|
||||||
throw new \Exception('Invalid Authorization header format');
|
throw new \Exception('Invalid Authorization header format');
|
||||||
}
|
}
|
||||||
|
// Username and password test
|
||||||
|
$decoded = explode(':', base64_decode($matches[1]), 2);
|
||||||
|
$authorized = empty(array_diff([ $this->config->secret('api_access_username'), $this->config->secret('api_access_password')], $decoded));
|
||||||
|
if (!$authorized) {
|
||||||
|
throw new \Exception('Authorization failed');
|
||||||
|
}
|
||||||
|
|
||||||
$token = $matches[1];
|
// Now, for the X-API-Key only if it was defined in the config (simple way to disable it for testing)
|
||||||
$expected = $this->config->secret('api_access_token');
|
$expectedApiKey = $this->config->secret('api_access_token');
|
||||||
|
if ($expectedApiKey !== null && trim($expectedApiKey) !== '') {
|
||||||
if (empty($expected) || !hash_equals((string) $expected, (string) $token)) {
|
$apiKeyHeader = $_SERVER['HTTP_X_API_KEY'] ?? $_SERVER['REDIRECT_HTTP_X_API_KEY'] ?? '';
|
||||||
throw new \Exception('Invalid API access token');
|
if (!$apiKeyHeader) {
|
||||||
|
throw new \Exception('Missing API access token');
|
||||||
|
}
|
||||||
|
if (!hash_equals((string) $expectedApiKey, (string) $apiKeyHeader)) {
|
||||||
|
throw new \Exception('Invalid API access token');
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,4 +8,15 @@ class Response {
|
|||||||
echo json_encode($data);
|
echo json_encode($data);
|
||||||
exit;
|
exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function unauthorized(?string $data = null) {
|
||||||
|
http_response_code(401);
|
||||||
|
header('Content-Type: application/json');
|
||||||
|
header('HTTP/1.1 401 Unauthorized');
|
||||||
|
header('Content-Length: 0');
|
||||||
|
if ($data !== null && $data !== '') {
|
||||||
|
echo json_encode($data);
|
||||||
|
}
|
||||||
|
exit;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user