diff --git a/lib/galaxy/web/framework/middleware/remoteuser.py b/lib/galaxy/web/framework/middleware/remoteuser.py index fb6c26a389f..918746dedde 100644 --- a/lib/galaxy/web/framework/middleware/remoteuser.py +++ b/lib/galaxy/web/framework/middleware/remoteuser.py @@ -74,8 +74,12 @@ class RemoteUser( object ): # seems improbable that an attacker with access to the server hosting # Galaxy would not have access to Galaxy itself, and be attempting to # attack the system - if self.config_secret_header is not None: - if not safe_str_cmp(environ.get('HTTP_GX_SECRET'), self.config_secret_header): + if path_info.startswith( '/api/' ): + # The API handles its own authentication via keys + # Check for API key before checking for header + return self.app( environ, start_response ) + elif self.config_secret_header is not None: + if not safe_str_cmp(environ.get('HTTP_GX_SECRET', ''), self.config_secret_header): title = "Access to Galaxy is denied" message = """ Galaxy is configured to authenticate users via an external @@ -141,9 +145,6 @@ class RemoteUser( object ): """ return self.error( start_response, title, message ) return self.app( environ, start_response ) - elif path_info.startswith( '/api/' ): - # The API handles its own authentication via keys - return self.app( environ, start_response ) else: title = "Access to Galaxy is denied" message = """