Mercurial > hg > isophonics-drupal-site
view core/modules/basic_auth/src/PageCache/DisallowBasicAuthRequests.php @ 17:129ea1e6d783
Update, including to Drupal core 8.6.10
author | Chris Cannam |
---|---|
date | Thu, 28 Feb 2019 13:21:36 +0000 |
parents | 4c8ae668cc8c |
children |
line wrap: on
line source
<?php namespace Drupal\basic_auth\PageCache; use Drupal\Core\PageCache\RequestPolicyInterface; use Symfony\Component\HttpFoundation\Request; /** * Cache policy for pages served from basic auth. * * This policy disallows caching of requests that use basic_auth for security * reasons. Otherwise responses for authenticated requests can get into the * page cache and could be delivered to unprivileged users. */ class DisallowBasicAuthRequests implements RequestPolicyInterface { /** * {@inheritdoc} */ public function check(Request $request) { $username = $request->headers->get('PHP_AUTH_USER'); $password = $request->headers->get('PHP_AUTH_PW'); if (isset($username) && isset($password)) { return self::DENY; } } }