aboutsummaryrefslogtreecommitdiffstats
path: root/apps/files_external
diff options
context:
space:
mode:
authorJohn Molakvoæ <skjnldsv@protonmail.com>2023-10-05 11:23:55 +0200
committerJohn Molakvoæ <skjnldsv@protonmail.com>2023-10-10 12:07:48 +0200
commitae29608e46c1a923fcf87fc89444f7e5dab8b404 (patch)
tree1b3addc60499f72b676a186e85d575f8242c58e6 /apps/files_external
parente6d0105217e9a89bb6fddcfda4830ac9a556ed86 (diff)
downloadnextcloud-server-ae29608e46c1a923fcf87fc89444f7e5dab8b404.tar.gz
nextcloud-server-ae29608e46c1a923fcf87fc89444f7e5dab8b404.zip
fix(files_external): basic auth user storage trigger
Signed-off-by: John Molakvoæ <skjnldsv@protonmail.com>
Diffstat (limited to 'apps/files_external')
-rw-r--r--apps/files_external/lib/Controller/ApiController.php1
-rw-r--r--apps/files_external/src/actions/enterCredentialsAction.ts8
2 files changed, 6 insertions, 3 deletions
diff --git a/apps/files_external/lib/Controller/ApiController.php b/apps/files_external/lib/Controller/ApiController.php
index 5a62a19e3cb..163d403dc2c 100644
--- a/apps/files_external/lib/Controller/ApiController.php
+++ b/apps/files_external/lib/Controller/ApiController.php
@@ -126,6 +126,7 @@ class ApiController extends OCSController {
/**
* @NoAdminRequired
+ * @NoCSRFRequired
*
* Ask for credentials using a browser's native basic auth prompt
* Then returns it if provided
diff --git a/apps/files_external/src/actions/enterCredentialsAction.ts b/apps/files_external/src/actions/enterCredentialsAction.ts
index eeb2f5f8793..162a359f488 100644
--- a/apps/files_external/src/actions/enterCredentialsAction.ts
+++ b/apps/files_external/src/actions/enterCredentialsAction.ts
@@ -75,11 +75,13 @@ export const action = new FileAction({
async exec(node: Node) {
// always resolve auth request, we'll process the data afterwards
- const response = await axios.get(generateOcsUrl('/apps/files_external/api/v1/auth'), {
- validateStatus: () => true,
+ // Using fetch as axios have integrated auth handling and X-Requested-With header
+ const response = await fetch(generateOcsUrl('/apps/files_external/api/v1/auth'), {
+ headers: new Headers({ Accept: 'application/json' }),
+ credentials: 'include',
})
- const data = (response?.data || {}) as OCSAuthResponse
+ const data = (await response?.json() || {}) as OCSAuthResponse
if (data.ocs.data.user && data.ocs.data.password) {
const configResponse = await axios.put(generateUrl('apps/files_external/userglobalstorages/{id}', node.attributes), {
backendOptions: data.ocs.data,