New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix broken CookieAuthenticationRedirect caused by PR #14036 for non-api requests #14399
Conversation
…en not in an API controller
Hi there @mwillebrands, thank you for this contribution! 👍 While we wait for one of the Core Collaborators team to have a look at your work, we wanted to let you know about that we have a checklist for some of the things we will consider during review:
Don't worry if you got something wrong. We like to think of a pull request as the start of a conversation, we're happy to provide guidance on improving your contribution. If you realize that you might want to make some changes then you can do that by adding new commits to the branch you created for this work and pushing new commits. They should then automatically show up as updates to this pull request. Thanks, from your friendly Umbraco GitHub bot 🤖 🙂 |
Hi @mwillebrands! Thanks for your PR to handle the surfacecontroller redirect to Access Denied. One of the Core Collaborators team will review this as soon as possible. However, in the meantime I am going to raise it internally just to check the desired behaviour of the redirect for a surface controller. Best wishes and someone will be in touch soon, Emma |
Hi @mwillebrands, Just to update this one, I have confirmed with HQ that the behaviour you describe sounds like a suitable fix. Someone from the core collaborators team will review it and hopefully merge it as soon as we can! Emma |
Amazing, thank you very much |
@emmagarland, I've created some integration tests for this scenario as well. Would you like these pushed into this PR as a seperate commit? |
That would be ideal, thank you! Emma |
…ber-authorize-returns-401-instead-of-redirect-on-surface-controllers # Conflicts: # src/Umbraco.Web.Common/Security/ConfigureMemberCookieOptions.cs
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I've tested the changes and they work as intended, thanks for the fix @mwillebrands 🙌
Cherry picked for v10/11 in 3f196a9 |
Details
With Pull Request #14036 a fix has been introduced which makes sure that instances of the
UmbracoApiController
return a 403 and 401 instead of redirecting to theAccessDeniedPath
which is configured in theCookieAuthenticationOptions
. This feature works, however as a side effect, instances ofSurfaceController
are also affected by this, and they don't redirect anymore to theAccessDeniedPath
, which in my opinion is still wanted functionality.I've altered the
UmbracoMemberAuthorizeFilter
so it always returns aForbidResult
as that's the only result that is explicitly handled by theCookieAuthenticationHandler
and this makes sure the functionality is the same as before the changes in #14036 except for theUmbracoApiController
. The default redirect behaviour can still be overridden in theCookieAuthenticationOptions
.Test
You can use the same test cases as in the original Pull Request, however do a test case with an UmbracoAPIController and a SurfaceController.
Expected Results
ApiController
Not logged in should return a 401 status code
Not authorized should return a 403 status code
Surfacecontroller
Not logged in should return a redirect to the AccessDeniedPath that is configured in the
CookieAuthenticationOptions
Not authorized should return a redirect to the AccessDeniedPath that is configured in the
CookieAuthenticationOptions