Commit de0781fd authored by Byron Jones's avatar Byron Jones

Bug 1139755: Allow API authentication with X-Headers

r=dkl,a=glob
parent 243d66a3
......@@ -379,7 +379,7 @@ sub _argument_type_check {
# Update the params to allow for several convenience key/values
# use for authentication
fix_credentials($params);
fix_credentials($params, $self->cgi);
Bugzilla->input_params($params);
......
......@@ -76,7 +76,7 @@ sub handle {
my $params = $self->_retrieve_json_params;
fix_credentials($params);
fix_credentials($params, $self->cgi);
# Fix includes/excludes for each call
rest_include_exclude($params);
......
......@@ -16,6 +16,7 @@ use Bugzilla::FlagType;
use Bugzilla::Error;
use Storable qw(dclone);
use URI::Escape qw(uri_unescape);
use parent qw(Exporter);
......@@ -260,8 +261,25 @@ sub params_to_objects {
return \@objects;
}
use constant X_HEADERS => {
X_BUGZILLA_LOGIN => 'Bugzilla_login',
X_BUGZILLA_PASSWORD => 'Bugzilla_password',
X_BUGZILLA_API_KEY => 'Bugzilla_api_key',
X_BUGZILLA_TOKEN => 'Bugzilla_token',
};
sub fix_credentials {
my ($params) = @_;
my ($params, $cgi) = @_;
# Allow user to pass in authentication details in X-Headers
# This allows callers to keep credentials out of GET request query-strings
if ($cgi) {
foreach my $field (keys %{ X_HEADERS() }) {
next if exists $params->{X_HEADERS->{$field}} || $cgi->http($field) eq '';
$params->{X_HEADERS->{$field}} = uri_unescape($cgi->http($field));
}
}
# Allow user to pass in login=foo&password=bar as a convenience
# even if not calling GET /login. We also do not delete them as
# GET /login requires "login" and "password".
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment