浏览代码

allow from ui header

Abhishek Kondur 1 年之前
父节点
当前提交
8e3853afb2
共有 2 个文件被更改,包括 2 次插入2 次删除
  1. 1 1
      controllers/controller.go
  2. 1 1
      controllers/user.go

+ 1 - 1
controllers/controller.go

@@ -41,7 +41,7 @@ func HandleRESTRequests(wg *sync.WaitGroup, ctx context.Context) {
 
 
 	// Currently allowed dev origin is all. Should change in prod
 	// Currently allowed dev origin is all. Should change in prod
 	// should consider analyzing the allowed methods further
 	// should consider analyzing the allowed methods further
-	headersOk := handlers.AllowedHeaders([]string{"Access-Control-Allow-Origin", "X-Requested-With", "Content-Type", "authorization", "From-UI"})
+	headersOk := handlers.AllowedHeaders([]string{"Access-Control-Allow-Origin", "X-Requested-With", "Content-Type", "authorization", "From-Ui"})
 	originsOk := handlers.AllowedOrigins(strings.Split(servercfg.GetAllowedOrigin(), ","))
 	originsOk := handlers.AllowedOrigins(strings.Split(servercfg.GetAllowedOrigin(), ","))
 	methodsOk := handlers.AllowedMethods([]string{http.MethodGet, http.MethodPut, http.MethodPost, http.MethodDelete})
 	methodsOk := handlers.AllowedMethods([]string{http.MethodGet, http.MethodPut, http.MethodPost, http.MethodDelete})
 
 

+ 1 - 1
controllers/user.go

@@ -62,7 +62,7 @@ func authenticateUser(response http.ResponseWriter, request *http.Request) {
 		return
 		return
 	}
 	}
 
 
-	if val := request.Header.Get("From-UI"); val == "true" {
+	if val := request.Header.Get("From-Ui"); val == "true" {
 		// request came from UI, if normal user block Login
 		// request came from UI, if normal user block Login
 		user, err := logic.GetUser(authRequest.UserName)
 		user, err := logic.GetUser(authRequest.UserName)
 		if err != nil {
 		if err != nil {