* deactivate deprecated auto-mapping * use native month-picker with fallback on old browser * bump dependencies to new major versions * replace deprecated ARRAY column type with JSON * named arguments * nullable arguments * native lazy ghosts * update routes to use php config * disable PHP < 8.4 * use static RTL configuration * new qr code package * clear out env file * recipe updates * fix deprecations * preset new env variable if not existing * bump maria db version examples * remove deprecated api-token support * fix validator deprecations * remove timesheet category column * fix broken validator autoconfiguration * stabilize tests * fix migration syntax compatibility * fix doctrine deprecation * fix datetime format * remove constructor dependency * only include visible preferences in invoice templates * fix test container dependency * removed ProjectConstraint multi-constraint logic * allow to disable plugins in certain environments * refactor TimesheetConstraint to non-service * activate new interface methods * prevent update issues with .env * improved customer fixture * removed $user->isExportDecimal()
41 lines
1.4 KiB
PHP
41 lines
1.4 KiB
PHP
<?php
|
|
|
|
/*
|
|
* This file is part of the Kimai time-tracking app.
|
|
*
|
|
* For the full copyright and license information, please view the LICENSE
|
|
* file that was distributed with this source code.
|
|
*/
|
|
|
|
namespace App\API\Authentication;
|
|
|
|
use Symfony\Component\HttpFoundation\Request;
|
|
use Symfony\Component\HttpFoundation\RequestMatcherInterface;
|
|
|
|
final class ApiRequestMatcher implements RequestMatcherInterface
|
|
{
|
|
public function matches(Request $request): bool
|
|
{
|
|
// we do not want to handle URLs that are not in the API scope
|
|
if (!str_starts_with($request->getRequestUri(), '/api/')) {
|
|
return false;
|
|
}
|
|
|
|
// API documentation is only available to registered and logged-in users
|
|
if (str_starts_with($request->getRequestUri(), '/api/doc')) {
|
|
return false;
|
|
}
|
|
|
|
// let's use this firewall if a Bearer token is set in the header
|
|
// other cases like "bearer" are rejected earlier
|
|
if (($auth = $request->headers->get('Authorization')) !== null && str_starts_with($auth, 'Bearer ')) {
|
|
return true;
|
|
}
|
|
|
|
// checking for a previous session allows us to skip the API firewall and token access handler
|
|
// we simply re-use the existing session when doing API calls from the frontend.
|
|
// it is not necessary to check headers. if there is no valid session, we should always use this firewall
|
|
return !$request->hasPreviousSession();
|
|
}
|
|
}
|