mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Merge pull request #1801 from MatthewRalston/api_key_patch
[15.10] Checks for api_key before checking for header from SSO.
This commit is contained in:
@@ -74,8 +74,12 @@ class RemoteUser( object ):
|
||||
# seems improbable that an attacker with access to the server hosting
|
||||
# Galaxy would not have access to Galaxy itself, and be attempting to
|
||||
# attack the system
|
||||
if self.config_secret_header is not None:
|
||||
if not safe_str_cmp(environ.get('HTTP_GX_SECRET'), self.config_secret_header):
|
||||
if path_info.startswith( '/api/' ):
|
||||
# The API handles its own authentication via keys
|
||||
# Check for API key before checking for header
|
||||
return self.app( environ, start_response )
|
||||
elif self.config_secret_header is not None:
|
||||
if not safe_str_cmp(environ.get('HTTP_GX_SECRET', ''), self.config_secret_header):
|
||||
title = "Access to Galaxy is denied"
|
||||
message = """
|
||||
Galaxy is configured to authenticate users via an external
|
||||
@@ -141,9 +145,6 @@ class RemoteUser( object ):
|
||||
"""
|
||||
return self.error( start_response, title, message )
|
||||
return self.app( environ, start_response )
|
||||
elif path_info.startswith( '/api/' ):
|
||||
# The API handles its own authentication via keys
|
||||
return self.app( environ, start_response )
|
||||
else:
|
||||
title = "Access to Galaxy is denied"
|
||||
message = """
|
||||
|
||||
Reference in New Issue
Block a user