From 54c7440769b4a925efbbff5b245d612e735b91bd Mon Sep 17 00:00:00 2001 From: Michael Geers Date: Thu, 18 Apr 2024 06:13:01 +0200 Subject: [PATCH] fix: ignore basic auth header (#13473) --- server/http_auth.go | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/server/http_auth.go b/server/http_auth.go index e7b93089a..860ee7a85 100644 --- a/server/http_auth.go +++ b/server/http_auth.go @@ -3,6 +3,7 @@ package server import ( "encoding/json" "net/http" + "strings" "time" "github.com/evcc-io/evcc/util/auth" @@ -55,14 +56,19 @@ func updatePasswordHandler(auth auth.Auth) http.HandlerFunc { // read jwt from header and cookie func jwtFromRequest(r *http.Request) string { - tokenString := r.Header.Get("Authorization") - if tokenString == "" { - if cookie, _ := r.Cookie(authCookieName); cookie != nil { - tokenString = cookie.Value - } + // read from header + authHeader := r.Header.Get("Authorization") + splitToken := strings.Split(authHeader, "Bearer ") + if len(splitToken) == 2 { + return splitToken[1] } - return tokenString + // read from cookie + if cookie, _ := r.Cookie(authCookieName); cookie != nil { + return cookie.Value + } + + return "" } // authStatusHandler login status (true/false) based on jwt token. Error if admin password is not configured