Merge pull request #1801 from MatthewRalston/api_key_patch

[15.10] Checks for api_key before checking for header from SSO.
This commit is contained in:
Dannon Baker
2016-03-22 11:53:45 -04:00
@@ -74,8 +74,12 @@ class RemoteUser( object ):
# seems improbable that an attacker with access to the server hosting
# Galaxy would not have access to Galaxy itself, and be attempting to
# attack the system
if self.config_secret_header is not None:
if not safe_str_cmp(environ.get('HTTP_GX_SECRET'), self.config_secret_header):
if path_info.startswith( '/api/' ):
# The API handles its own authentication via keys
# Check for API key before checking for header
return self.app( environ, start_response )
elif self.config_secret_header is not None:
if not safe_str_cmp(environ.get('HTTP_GX_SECRET', ''), self.config_secret_header):
title = "Access to Galaxy is denied"
message = """
Galaxy is configured to authenticate users via an external
@@ -141,9 +145,6 @@ class RemoteUser( object ):
"""
return self.error( start_response, title, message )
return self.app( environ, start_response )
elif path_info.startswith( '/api/' ):
# The API handles its own authentication via keys
return self.app( environ, start_response )
else:
title = "Access to Galaxy is denied"
message = """