Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions src/Helpers/HeaderExtractor.php
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
namespace Firesphere\GraphQLJWT\Helpers;

use SilverStripe\Control\HTTPRequest;
use \SilverStripe\Core\Environment;

class HeaderExtractor
{
Expand All @@ -14,6 +15,13 @@ class HeaderExtractor
public static function getAuthorizationHeader(HTTPRequest $request)
{
$authHeader = $request->getHeader('Authorization');
if (!$authHeader) {
$envVars = Environment::getVariables();
if (isset($envVars['_SERVER']['REDIRECT_HTTP_AUTHORIZATION'])) {
Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I believe this should be an .htaccess setting, which should forward the HTTP authorisation. Not something inside the scope of this module?

Copy link
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A bit late, but on second thought, I do see value in this, but I'd rather not reed directly from a header, could you update this to use filter_input?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I suppose I could, shouldn’t be hard. But it’s been a while and I don’t have that setup anymore where this was an issue, so can’t actually test it now. Try to find a moment to set something up...

$authHeader = $envVars['_SERVER']['REDIRECT_HTTP_AUTHORIZATION'];
}
}

if ($authHeader && preg_match('/Bearer\s+(.*)$/i', $authHeader, $matches)) {
return $matches;
}
Expand Down