我想扩展Restler以检查是否传递了自定义标头授权的有效值.我无法解决问题,我试过这个,但没有机会:
class AuthenticateMe implements iAuthenticate() {
function __isAuthenticated() {
//return isset($_SERVER['HTTP_AUTH_KEY']) && $_SERVER['HTTP_AUTH_KEY']==AuthenticateMe::KEY ? TRUE : FALSE;
$headers = apache_request_headers();
foreach ($headers as $header => $value) {
if($header == "Authorization") {
return TRUE;
} else {
//return FALSE;
throw new RestException(404);
}
}
}
}
Run Code Online (Sandbox Code Playgroud)
让我快速修复您的自定义身份验证标头示例
class HeaderAuth implements iAuthenticate{
function __isAuthenticated(){
//we are only looking for a custom header called 'Auth'
//but $_SERVER prepends HTTP_ and makes it all uppercase
//thats why we need to look for 'HTTP_AUTH' instead
//also do not use header 'Authorization'. It is not
//included in PHP's $_SERVER variable
return isset($_SERVER['HTTP_AUTH']) && $_SERVER['HTTP_AUTH']=='password';
}
}
Run Code Online (Sandbox Code Playgroud)
我测试过它以确保它有效!
以下是如何使其与Authorization标头一起使用,它仅适用于apache服务器
class Authorization implements iAuthenticate{
function __isAuthenticated(){
$headers = apache_request_headers();
return isset($headers['Authorization']) && $headers['Authorization']=='password';
}
}
Run Code Online (Sandbox Code Playgroud)
我想通了,PHP转换Authorization报头插入到$_SERVER['PHP_AUTH_DIGEST']或$_SERVER['PHP_AUTH_USER']与$_SERVER['PHP_AUTH_PW']根据AUTH请求的类型(摘要或碱性),我们可以使用下面的.htaccess文件,以使$_SERVER['HTTP_AUTHORIZATION']头
DirectoryIndex index.php
DirectoryIndex index.php
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule ^$ index.php [QSA,L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^(.*)$ index.php [QSA,L]
RewriteRule .* - [env=HTTP_AUTHORIZATION:%{HTTP:Authorization},last]
</IfModule>
Run Code Online (Sandbox Code Playgroud)
重要的部分是RewriteRule.* - [env = HTTP_AUTHORIZATION:%{HTTP:Authorization},last]
现在我们的例子可以简化为:
class Authorization implements iAuthenticate{
function __isAuthenticated(){
return isset($_SERVER['HTTP_AUTHORIZATION']) && $_SERVER['HTTP_AUTHORIZATION']=='password';
}
}
Run Code Online (Sandbox Code Playgroud)