【问题标题】:Cakephp3 Tiny Auth Allow Auth failCakephp3 Tiny Auth 允许 Auth 失败
【发布时间】:2019-06-07 22:57:05
【问题描述】:

我在我的 Cakephp3 中使用 TinyAuth 插件。我有一个具有以下命名空间的控制器:

namespace App\Controller\Api\Datatables;

控制器是Listings,我的功能是Filter

我有以下路线设置:

Router::scope('/datatables', ['prefix' => 'api/datatables'], function (RouteBuilder $routes) {
    $routes->extensions(['json', 'xml', 'ajax']);   
    $routes->fallbacks(DashedRoute::class);
});

这允许我调用以下网址:

/datatables/listings/filter.json

我要允许过滤功能:

datatables/Listings = filter

当我调用我的 URL 时,我被重定向到登录。如果我登录 url 有效,那么 allow_auth 有效。

我还尝试了以下方法:

api/datatables/Listings = filter
api/Datatables/Listings = filter
Api/Datatables/Listings = filter
api/datatables/Listings = filter
datatables/Listings = filter
Datatables/Listings = filter
api/Listings = filter

不管是什么路径都是不允许的。如果我将控制器移动到默认位置,那么在 allow_auth 中:

Listings = filter

过滤功能无需授权即可访问。这表明在使用路由器作用域时插件存在问题。

这是插件的composer.json

{
    "name": "ypnos-web/cakephp-datatables",
    "description": "jQuery DataTables for CakePHP 3",
    "homepage": "https://github.com/ypnos-web/cakephp-datatables",
    "type": "cakephp-plugin",
    "keywords": ["cakephp", "datatables"],
    "license": "MIT",
    "authors": [
        {
            "name": "Frank Heider",
            "homepage": "https://github.com/fheider",
            "role": "Author"
        },
        {
            "name": "Johannes Jordan",
            "homepage": "https://github.com/ypnos-web",
            "role": "Author"
        }
    ],
    "require": {
        "php": ">=7.0",
        "cakephp/cakephp": "^3.6"
    },
    "autoload": {
        "psr-4": {
            "DataTables\\": "src"
        }
    },
    "autoload-dev": {
        "psr-4": {
            "DataTables\\Test\\": "tests",
            "Cake\\Test\\": "./vendor/cakephp/cakephp/tests"
        }
    }
}

我是否正确地说斜线路由确实适用于 acl.ini - 据我所知,它们似乎是正确的。

我正在使用斜线来更好地组织我的功能。

我调用/datatables/listings/filter.json时的请求参数如下?

'controller' => 'Listings',
    'action' => 'filter',
    'pass' => [],
    'prefix' => 'api/datatables',
    'plugin' => null,
    '_ext' => 'json',
    '_matchedRoute' => '/datatables/:controller/:action/*',
    '?' => [
        'string' => 'seat'
    ]

如果我调用 /api/datatables/listings/filter.json:

找不到控制器类数据表。

【问题讨论】:

  • 我很好奇$this->request->params包含什么,这里的路由数组里到底是什么数据?这才是最重要的,而不是您的命名空间(PHP 内部)或斜杠前缀(公共 URL 内部)
  • @mark 我应该在哪里调试我的请求参数?
  • 在您尝试调试的控制器内部,以及在 initialize() 等内部无法访问的地方
  • 请查看我更新的参数问题

标签: authentication cakephp cakephp-3.x


【解决方案1】:

我对插件不太熟悉,但api/datatables/Listings 似乎是正确的格式,但是查看插件的源代码,似乎不支持嵌套前缀:

if (strpos($key, '/') !== false) {
    list($res['prefix'], $key) = explode('/', $key);
}

https://github.com/dereuromark/cakephp-tinyauth/blob/1.11.0/src/Utility/Utility.php#L23-L25

该代码会将api 解析为前缀,并将datatables 解析为控制器。

您可能想打开一个问题,或者如果可以的话,自己添加对它的支持。

【讨论】:

  • 是的,我认为多斜线在 CakePHP 中甚至不是一个有效/预期的东西。应该避免这些。但你的问题似乎不同。您使用的是生成的路由,而不是记录在案的默认 URL 部分。请同时发布您的实际插件名称和 composer.json。
  • @mark 你可能想对这个问题发表评论:) 不管怎样,这就是嵌套前缀在 CakePHP 中的表达方式?还是您指的是使用斜线分隔前缀和控制器的 auth 插件?
  • 没错,我对这个问题添加了评论。至于你的回答:如果这能解决问题,我很乐意接受一个 PR,其中包括使用最后一个 / 而不是第一个 / 的变化。
  • 感谢您的支持 - github.com/dereuromark/cakephp-tinyauth/pull/104 应该可以解决这个问题。请确认。
猜你喜欢
  • 2014-11-19
  • 2014-10-03
  • 1970-01-01
  • 2019-07-07
  • 1970-01-01
  • 2016-09-27
  • 2018-01-24
  • 2016-08-27
  • 2019-01-30
相关资源
最近更新 更多