From 31f25c6693be7063a5595a23a71da1f9d33621d7 Mon Sep 17 00:00:00 2001 From: Jan-Hendrik Willms <tleilax+studip@gmail.com> Date: Tue, 28 May 2024 18:20:09 +0000 Subject: [PATCH] fixes #1971 Merge request studip/studip!3048 --- .../JsonApi/Middlewares/Auth/OAuth1Strategy.php | 11 +---------- 1 file changed, 1 insertion(+), 10 deletions(-) diff --git a/lib/classes/JsonApi/Middlewares/Auth/OAuth1Strategy.php b/lib/classes/JsonApi/Middlewares/Auth/OAuth1Strategy.php index 113ee09afe6..20d22e2ef26 100644 --- a/lib/classes/JsonApi/Middlewares/Auth/OAuth1Strategy.php +++ b/lib/classes/JsonApi/Middlewares/Auth/OAuth1Strategy.php @@ -57,16 +57,7 @@ class OAuth1Strategy implements Strategy $uri = (string) $this->request->getUri(); $method = $this->request->getMethod(); - if ('GET' === strtoupper(($method))) { - $parameters = (array) $this->request->getQueryParams(); - } elseif ('POST' === strtoupper(($method))) { - $parameters = (array) $this->request->getParsedBody(); - } else { - $parameters = []; - } - $parameters = $this->getParamsFromAuthorizationHeader($this->request, $parameters); - - $req = new \OAuthRequestVerifier($uri, $method, $parameters); + $req = new \OAuthRequestVerifier($uri, $method); // Check oauth timestamp and deny access if timestamp is outdated if ($req->getParam('oauth_timestamp') < strtotime('-6 hours')) { -- GitLab