Provider auth: require authenticated session for OAuth login/logout (#33115)

Co-authored-by: Michael Geers <michael@geers.tv>
This commit is contained in:
Tilo Alexander 2026-08-24 15:47:06 +02:00 • committed by GitHub
parent 226425e22e
commit 4adbf141d6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
7 changed files with 65 additions and 17 deletions

View file

@ -481,10 +481,11 @@ func runRoot(cmd *cobra.Command, args []string) {
once.Do(func() { close(stopC) }) // signal loop to end
}()
// allow web access for vehicles
configureAuth(httpd.Router(), valueChan)
authObject := auth.New()
// allow web access for vehicles
configureAuth(httpd.Router(), server.EnsureAuthHandler(authObject), valueChan)
if ok, _ := cmd.Flags().GetBool(flagDisableAuth); ok {
log.WARN.Println("❗❗❗ Authentication is disabled. This is dangerous. Your data and credentials are not protected.")
authObject.SetAuthMode(auth.Disabled)

View file

@ -1544,7 +1544,7 @@ func configureLoadpoints(conf globalconfig.All) error {
}
// configureAuth handles routing for devices. For now only api.AuthProvider related routes
func configureAuth(router *mux.Router, paramC chan<- util.Param) {
func configureAuth(router *mux.Router, authMiddleware mux.MiddlewareFunc, paramC chan<- util.Param) {
auth := router.PathPrefix("/providerauth").Subrouter()
auth.Use(handlers.CompressHandler)
auth.Use(handlers.CORS(
@ -1554,8 +1554,8 @@ func configureAuth(router *mux.Router, paramC chan<- util.Param) {
// backwards-compatible revert of https://github.com/evcc-io/evcc/pull/21266
router.PathPrefix("/oauth").Handler(auth)
// wire the handler
providerauth.Setup(auth, paramC)
// wire the handler; login/logout require an authenticated session
providerauth.Setup(auth, paramC, authMiddleware)
}
// isExperimental returns if experimental features are enabled