Respond with HTTP status code 403 when an XHR requires authentication
refs #8626
This commit is contained in:
parent
0806ab3ec9
commit
2f752ed1ac
|
@ -299,6 +299,8 @@ class ActionController extends Zend_Controller_Action
|
|||
* if it's an auto-refresh request or to redirect to the URL which required login if it's not an auto-refreshing
|
||||
* one.
|
||||
*
|
||||
* XHR will respond with HTTP status code 403 Forbidden.
|
||||
*
|
||||
* @param Url|string $redirect URL to redirect to after successful login
|
||||
*/
|
||||
protected function redirectToLogin($redirect = null)
|
||||
|
@ -306,6 +308,7 @@ class ActionController extends Zend_Controller_Action
|
|||
$login = Url::fromPath('authentication/login');
|
||||
if ($this->isXhr()) {
|
||||
$login->setParam('redirect', '__SELF__');
|
||||
$this->_response->setHttpResponseCode(403);
|
||||
} elseif ($redirect !== null) {
|
||||
if (! $redirect instanceof Url) {
|
||||
$redirect = Url::fromPath($redirect);
|
||||
|
|
Loading…
Reference in New Issue