mirror of
https://github.com/suitenumerique/meet.git
synced 2026-10-09 06:50:54 +00:00
🐛(backend) use the configured token type in BaseJWTAuthentication
authenticate and authenticate_header hardcoded "Bearer" instead of using the token type the backend is configured with. Setting APPLICATION_JWT_TOKEN_TYPE, ADDONS_TOKEN_TYPE or USER_ACCESS_TOKEN_TYPE to anything else made every token be ignored, since the Authorization scheme never matched. Store the token type on the backend and use it both to match the Authorization header scheme (case-insensitively) and as the WWW-Authenticate scheme.
This commit is contained in:
@@ -48,6 +48,7 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
|
||||
|
||||
self.is_enabled = is_enabled
|
||||
self._token_service = None
|
||||
self._token_type = token_type
|
||||
|
||||
if not self.is_enabled:
|
||||
return
|
||||
@@ -73,7 +74,10 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
|
||||
|
||||
auth_header = authentication.get_authorization_header(request).split()
|
||||
|
||||
if not auth_header or auth_header[0].lower() != b"bearer":
|
||||
if (
|
||||
not auth_header
|
||||
or auth_header[0].lower() != self._token_type.lower().encode()
|
||||
):
|
||||
# Defer to next authentication backend
|
||||
return None
|
||||
|
||||
@@ -159,7 +163,7 @@ class BaseJWTAuthentication(authentication.BaseAuthentication):
|
||||
|
||||
def authenticate_header(self, request):
|
||||
"""Return authentication scheme for WWW-Authenticate header."""
|
||||
return "Bearer"
|
||||
return self._token_type
|
||||
|
||||
def authenticate_credentials(self, token):
|
||||
"""Validate JWT token and return authenticated user.
|
||||
|
||||
Reference in New Issue
Block a user