Don't use anonymous access after access token expires

This commit is contained in:
Eduard Heimbuch
2019-11-12 13:49:37 +01:00
parent f0f134daeb
commit 234d98aee7
2 changed files with 3 additions and 2 deletions

View File

@@ -127,7 +127,7 @@ public class AuthenticationFilter extends HttpFilter
logger.trace("user is already authenticated");
processChain(request, response, chain, subject);
}
else if (isAnonymousAccessEnabled())
else if (isAnonymousAccessEnabled() && !HttpUtil.isWUIRequest(request))
{
logger.trace("anonymous access granted");
subject.login(new AnonymousToken());

View File

@@ -7,7 +7,8 @@ const applyFetchOptions: (p: RequestInit) => RequestInit = o => {
o.headers = {
Cache: "no-cache",
// identify the request as ajax request
"X-Requested-With": "XMLHttpRequest"
"X-Requested-With": "XMLHttpRequest",
"X-SCM-Client": "WUI"
};
return o;
};