mirror of
https://github.com/dani-garcia/vaultwarden
synced 2024-12-14 09:33:44 +01:00
Fixing issue #908
Sometimes an org-uuid is not within the path but in a query value, This fixes the check for that.
This commit is contained in:
parent
b85d548879
commit
669b101e6a
1 changed files with 52 additions and 33 deletions
29
src/auth.rs
29
src/auth.rs
|
@ -315,9 +315,28 @@ impl<'a, 'r> FromRequest<'a, 'r> for OrgHeaders {
|
|||
Outcome::Forward(_) => Outcome::Forward(()),
|
||||
Outcome::Failure(f) => Outcome::Failure(f),
|
||||
Outcome::Success(headers) => {
|
||||
// org_id is expected to be the second param ("/organizations/<org_id>")
|
||||
match request.get_param::<String>(1) {
|
||||
Some(Ok(org_id)) => {
|
||||
// org_id is usually the second param ("/organizations/<org_id>")
|
||||
// But there are cases where it is located in a query value.
|
||||
// First check the param, if this is not a valid uuid, we will try the query value.
|
||||
let query_org_id = match request.get_query_value::<String>("organizationId") {
|
||||
Some(Ok(query_org_id)) => { query_org_id }
|
||||
_ => { "".into() }
|
||||
};
|
||||
let param_org_id = match request.get_param::<String>(1) {
|
||||
Some(Ok(param_org_id)) => { param_org_id }
|
||||
_ => { "".into() }
|
||||
};
|
||||
|
||||
let org_uuid: _ = match uuid::Uuid::parse_str(¶m_org_id) {
|
||||
Ok(uuid) => uuid,
|
||||
_ => match uuid::Uuid::parse_str(&query_org_id) {
|
||||
Ok(uuid) => uuid,
|
||||
_ => err_handler!("Error getting the organization id"),
|
||||
}
|
||||
};
|
||||
|
||||
let org_id: &str = &org_uuid.to_string();
|
||||
if !org_id.is_empty() {
|
||||
let conn = match request.guard::<DbConn>() {
|
||||
Outcome::Success(conn) => conn,
|
||||
_ => err_handler!("Error getting DB"),
|
||||
|
@ -348,8 +367,8 @@ impl<'a, 'r> FromRequest<'a, 'r> for OrgHeaders {
|
|||
}
|
||||
},
|
||||
})
|
||||
}
|
||||
_ => err_handler!("Error getting the organization id"),
|
||||
} else {
|
||||
err_handler!("Error getting the organization id")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
Loading…
Reference in a new issue