|
|
|
|
@ -38,6 +38,7 @@ use OCP\AppFramework\Http\JSONResponse;
|
|
|
|
|
use OCP\AppFramework\Http\Response;
|
|
|
|
|
use OCP\AppFramework\Middleware;
|
|
|
|
|
use OCP\IRequest;
|
|
|
|
|
use OCP\ISession;
|
|
|
|
|
use OCP\Security\Bruteforce\IThrottler;
|
|
|
|
|
use ReflectionMethod;
|
|
|
|
|
|
|
|
|
|
@ -91,6 +92,10 @@ class CORSMiddleware extends Middleware {
|
|
|
|
|
if ($this->request->passesCSRFCheck()) {
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
// Skip CORS check for requests with AppAPI auth.
|
|
|
|
|
if ($this->session->getSession() instanceof ISession && $this->session->getSession()->get('app_api') === true) {
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
$this->session->logout();
|
|
|
|
|
try {
|
|
|
|
|
if ($user === null || $pass === null || !$this->session->logClientIn($user, $pass, $this->request, $this->throttler)) {
|
|
|
|
|
|