mirror of
https://github.com/elyby/accounts.git
synced 2024-11-27 01:02:06 +05:30
Исправлена проверка авторизации для запроса на refresh-token
This commit is contained in:
parent
f2e6df4022
commit
6d4bef0549
@ -110,7 +110,7 @@ class Component extends YiiUserComponent {
|
|||||||
return $result;
|
return $result;
|
||||||
}
|
}
|
||||||
|
|
||||||
public function renew(AccountSession $session) {
|
public function renew(AccountSession $session): RenewResult {
|
||||||
$account = $session->account;
|
$account = $session->account;
|
||||||
$transaction = Yii::$app->db->beginTransaction();
|
$transaction = Yii::$app->db->beginTransaction();
|
||||||
try {
|
try {
|
||||||
|
@ -17,13 +17,14 @@ class AuthenticationController extends Controller {
|
|||||||
public function behaviors() {
|
public function behaviors() {
|
||||||
return ArrayHelper::merge(parent::behaviors(), [
|
return ArrayHelper::merge(parent::behaviors(), [
|
||||||
'authenticator' => [
|
'authenticator' => [
|
||||||
'except' => ['login', 'forgot-password', 'recover-password', 'refresh-token'],
|
'only' => ['logout'],
|
||||||
],
|
],
|
||||||
'access' => [
|
'access' => [
|
||||||
'class' => AccessControl::class,
|
'class' => AccessControl::class,
|
||||||
|
'except' => ['refresh-token'],
|
||||||
'rules' => [
|
'rules' => [
|
||||||
[
|
[
|
||||||
'actions' => ['login', 'forgot-password', 'recover-password', 'refresh-token'],
|
'actions' => ['login', 'forgot-password', 'recover-password'],
|
||||||
'allow' => true,
|
'allow' => true,
|
||||||
'roles' => ['?'],
|
'roles' => ['?'],
|
||||||
],
|
],
|
||||||
|
Loading…
Reference in New Issue
Block a user