fix org keys auth

This commit is contained in:
Matej Bačo
2026-02-16 16:14:43 +01:00
parent 1a2238afaa
commit c7bbf6a987
2 changed files with 11 additions and 2 deletions
+8 -2
View File
@@ -169,8 +169,10 @@ Http::init()
// Handle special app role case
if ($apiKey->getRole() === User::ROLE_APPS) {
// Disable authorization checks for API keys
$authorization->setDefaultStatus(false);
// Disable authorization checks for project API keys
if ($project->getId() !== 'console') {
$authorization->setDefaultStatus(false);
}
$user = new User([
'$id' => '',
@@ -245,6 +247,10 @@ Http::init()
}
}
$authorization->addRole(Role::team($team->getId())->toString());
$authorization->addRole(Role::team($team->getId(), 'owner')->toString());
$authorization->addRole(Role::member($team->getId())->toString());
$queueForAudits->setUser($user);
}
} // Admin User Authentication
+3
View File
@@ -1304,6 +1304,7 @@ Http::setResource('team', function (Document $project, Database $dbForPlatform,
} else {
$route = $utopia->match($request);
$path = !empty($route) ? $route->getPath() : $request->getURI();
$orgHeader = $request->getHeader('x-appwrite-organization', '');
if (str_starts_with($path, '/v1/projects/:projectId')) {
$uri = $request->getURI();
$pid = explode('/', $uri)[3];
@@ -1318,6 +1319,8 @@ Http::setResource('team', function (Document $project, Database $dbForPlatform,
$team = $authorization->skip(fn () => $dbForPlatform->getDocument('teams', $teamId));
return $team;
} elseif (!empty($orgHeader)) {
return $authorization->skip(fn () => $dbForPlatform->getDocument('teams', $orgHeader));
}
}