Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
erp5
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
alecs_myu
erp5
Commits
6c3db78b
Commit
6c3db78b
authored
Oct 07, 2018
by
Cédric Le Ninivin
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
erp5_hal_json_style: Check if access is restricted prior traversing documents
parent
9da55ffb
Changes
1
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
19 additions
and
11 deletions
+19
-11
bt5/erp5_hal_json_style/SkinTemplateItem/portal_skins/erp5_hal_json_style/ERP5Document_getHateoas.py
...rtal_skins/erp5_hal_json_style/ERP5Document_getHateoas.py
+19
-11
No files found.
bt5/erp5_hal_json_style/SkinTemplateItem/portal_skins/erp5_hal_json_style/ERP5Document_getHateoas.py
View file @
6c3db78b
...
@@ -532,6 +532,20 @@ def parseActionUrl(url):
...
@@ -532,6 +532,20 @@ def parseActionUrl(url):
'url'
:
url
'url'
:
url
}
}
def
redirectToLoginForm
():
login_relative_url
=
site_root
.
getLayoutProperty
(
"configuration_login"
,
default
=
""
)
if
(
login_relative_url
):
response
.
setHeader
(
'WWW-Authenticate'
,
'X-Delegate uri="%s"'
%
(
url_template_dict
[
"login_template"
]
%
{
"root_url"
:
site_root
.
absolute_url
(),
"login"
:
login_relative_url
})
)
response
.
setStatus
(
401
)
return
""
def
getFormRelativeUrl
(
form
):
def
getFormRelativeUrl
(
form
):
return
portal
.
portal_catalog
(
return
portal
.
portal_catalog
(
portal_type
=
(
"ERP5 Form"
,
"ERP5 Report"
),
portal_type
=
(
"ERP5 Form"
,
"ERP5 Report"
),
...
@@ -1324,17 +1338,7 @@ def calculateHateoas(is_portal=None, is_site_root=None, traversed_document=None,
...
@@ -1324,17 +1338,7 @@ def calculateHateoas(is_portal=None, is_site_root=None, traversed_document=None,
}
}
if
(
restricted
==
1
)
and
(
portal
.
portal_membership
.
isAnonymousUser
()):
if
(
restricted
==
1
)
and
(
portal
.
portal_membership
.
isAnonymousUser
()):
login_relative_url
=
site_root
.
getLayoutProperty
(
"configuration_login"
,
default
=
""
)
return
redirectToLoginForm
()
if
(
login_relative_url
):
response
.
setHeader
(
'WWW-Authenticate'
,
'X-Delegate uri="%s"'
%
(
url_template_dict
[
"login_template"
]
%
{
"root_url"
:
site_root
.
absolute_url
(),
"login"
:
login_relative_url
})
)
response
.
setStatus
(
401
)
return
""
elif
mime_type
!=
traversed_document
.
Base_handleAcceptHeader
([
mime_type
]):
elif
mime_type
!=
traversed_document
.
Base_handleAcceptHeader
([
mime_type
]):
response
.
setStatus
(
406
)
response
.
setStatus
(
406
)
...
@@ -2187,6 +2191,10 @@ else:
...
@@ -2187,6 +2191,10 @@ else:
context.Base_prepareCorsResponse(RESPONSE=response)
context.Base_prepareCorsResponse(RESPONSE=response)
# Check if restricted prior traversing any documents
if (restricted == 1) and (portal.portal_membership.isAnonymousUser()):
return redirectToLoginForm()
# Check if traversed_document is the site_root
# Check if traversed_document is the site_root
if relative_url:
if relative_url:
temp_traversed_document = site_root.restrictedTraverse(relative_url, None)
temp_traversed_document = site_root.restrictedTraverse(relative_url, None)
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment