mirror of
https://github.com/appwrite/appwrite.git
synced 2026-05-26 13:51:13 +00:00
fix org keys auth
This commit is contained in:
@@ -169,8 +169,10 @@ Http::init()
|
||||
|
||||
// Handle special app role case
|
||||
if ($apiKey->getRole() === User::ROLE_APPS) {
|
||||
// Disable authorization checks for API keys
|
||||
$authorization->setDefaultStatus(false);
|
||||
// Disable authorization checks for project API keys
|
||||
if ($project->getId() !== 'console') {
|
||||
$authorization->setDefaultStatus(false);
|
||||
}
|
||||
|
||||
$user = new User([
|
||||
'$id' => '',
|
||||
@@ -245,6 +247,10 @@ Http::init()
|
||||
}
|
||||
}
|
||||
|
||||
$authorization->addRole(Role::team($team->getId())->toString());
|
||||
$authorization->addRole(Role::team($team->getId(), 'owner')->toString());
|
||||
$authorization->addRole(Role::member($team->getId())->toString());
|
||||
|
||||
$queueForAudits->setUser($user);
|
||||
}
|
||||
} // Admin User Authentication
|
||||
|
||||
@@ -1304,6 +1304,7 @@ Http::setResource('team', function (Document $project, Database $dbForPlatform,
|
||||
} else {
|
||||
$route = $utopia->match($request);
|
||||
$path = !empty($route) ? $route->getPath() : $request->getURI();
|
||||
$orgHeader = $request->getHeader('x-appwrite-organization', '');
|
||||
if (str_starts_with($path, '/v1/projects/:projectId')) {
|
||||
$uri = $request->getURI();
|
||||
$pid = explode('/', $uri)[3];
|
||||
@@ -1318,6 +1319,8 @@ Http::setResource('team', function (Document $project, Database $dbForPlatform,
|
||||
|
||||
$team = $authorization->skip(fn () => $dbForPlatform->getDocument('teams', $teamId));
|
||||
return $team;
|
||||
} elseif (!empty($orgHeader)) {
|
||||
return $authorization->skip(fn () => $dbForPlatform->getDocument('teams', $orgHeader));
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user