Merge pull request #284 from su77ungr/main
This commit is contained in:
@@ -238,6 +238,21 @@ pub async fn auth_middleware(
|
|||||||
}
|
}
|
||||||
Err(e) => {
|
Err(e) => {
|
||||||
tracing::warn!("App password verification failed: {}", e);
|
tracing::warn!("App password verification failed: {}", e);
|
||||||
|
// For WebDAV: include WWW-Authenticate so the client
|
||||||
|
// knows to re-prompt rather than silently failing.
|
||||||
|
if request.uri().path().starts_with("/webdav") {
|
||||||
|
return Ok(Response::builder()
|
||||||
|
.status(StatusCode::UNAUTHORIZED)
|
||||||
|
.header(
|
||||||
|
header::WWW_AUTHENTICATE,
|
||||||
|
r#"Basic realm="OxiCloud""#,
|
||||||
|
)
|
||||||
|
.header(header::CONTENT_TYPE, "text/plain; charset=utf-8")
|
||||||
|
.body(axum::body::Body::from(
|
||||||
|
"Invalid username or app password",
|
||||||
|
))
|
||||||
|
.unwrap());
|
||||||
|
}
|
||||||
return Err(AuthError::InvalidToken(
|
return Err(AuthError::InvalidToken(
|
||||||
"Invalid username or app password".to_string(),
|
"Invalid username or app password".to_string(),
|
||||||
));
|
));
|
||||||
@@ -291,12 +306,26 @@ pub async fn auth_middleware(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// No valid credentials found via any method
|
// No valid credentials found via any method.
|
||||||
if state.auth_service.is_none() {
|
if state.auth_service.is_none() {
|
||||||
tracing::error!("Auth middleware invoked but auth service is not configured");
|
tracing::error!("Auth middleware invoked but auth service is not configured");
|
||||||
return Err(AuthError::AuthServiceUnavailable);
|
return Err(AuthError::AuthServiceUnavailable);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// For WebDAV requests with no credentials at all: return 401 with
|
||||||
|
// WWW-Authenticate so that spec-compliant clients (Nautilus, Cyberduck,
|
||||||
|
// Windows Explorer, macOS Finder) know to prompt for a username/password.
|
||||||
|
// Non-WebDAV routes return the standard AuthError which renders without
|
||||||
|
// this header — keeping browser sessions redirecting to /login as before.
|
||||||
|
if request.uri().path().starts_with("/webdav") {
|
||||||
|
return Ok(Response::builder()
|
||||||
|
.status(StatusCode::UNAUTHORIZED)
|
||||||
|
.header(header::WWW_AUTHENTICATE, r#"Basic realm="OxiCloud""#)
|
||||||
|
.header(header::CONTENT_TYPE, "text/plain; charset=utf-8")
|
||||||
|
.body(axum::body::Body::from("Authentication required"))
|
||||||
|
.unwrap());
|
||||||
|
}
|
||||||
|
|
||||||
Err(AuthError::TokenNotProvided)
|
Err(AuthError::TokenNotProvided)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user