mirror of
https://github.com/scm-manager/scm-manager.git
synced 2025-11-15 09:46:16 +01:00
Don't use anonymous access after access token expires
This commit is contained in:
@@ -127,7 +127,7 @@ public class AuthenticationFilter extends HttpFilter
|
||||
logger.trace("user is already authenticated");
|
||||
processChain(request, response, chain, subject);
|
||||
}
|
||||
else if (isAnonymousAccessEnabled())
|
||||
else if (isAnonymousAccessEnabled() && !HttpUtil.isWUIRequest(request))
|
||||
{
|
||||
logger.trace("anonymous access granted");
|
||||
subject.login(new AnonymousToken());
|
||||
|
||||
@@ -7,7 +7,8 @@ const applyFetchOptions: (p: RequestInit) => RequestInit = o => {
|
||||
o.headers = {
|
||||
Cache: "no-cache",
|
||||
// identify the request as ajax request
|
||||
"X-Requested-With": "XMLHttpRequest"
|
||||
"X-Requested-With": "XMLHttpRequest",
|
||||
"X-SCM-Client": "WUI"
|
||||
};
|
||||
return o;
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user