aboutsummaryrefslogtreecommitdiff
path: root/lib/middleware
diff options
context:
space:
mode:
authorJan-Hendrik Willms <tleilax+studip@gmail.com>2026-03-17 18:48:19 +0100
committerJan-Hendrik Willms <tleilax+studip@gmail.com>2026-03-17 18:48:19 +0100
commit00a366d66d12a8934bc6ee5bebed45d7de1e8cc4 (patch)
tree1d4aa3597068bdc976c28b7ee52b5f3bc507c417 /lib/middleware
parenta628b6dda7863925893c1ec6ad7d7cf6c7c43564 (diff)
handle access denied exception correctly and don't duplicate redirect to login...
Closes #6375 Merge request studip/studip!4836 (cherry picked from commit 431fda0deda433186c5ea5740e2a2b120d2c1a14) 2fb81ba6 handle access denied exception correctly and don't duplicate redirect to login... Co-authored-by: Jan-Hendrik Willms <tleilax+studip@gmail.com>
Diffstat (limited to 'lib/middleware')
-rw-r--r--lib/middleware/HandleAccessDeniedMiddleware.php22
1 files changed, 7 insertions, 15 deletions
diff --git a/lib/middleware/HandleAccessDeniedMiddleware.php b/lib/middleware/HandleAccessDeniedMiddleware.php
index 567eca8..829b516 100644
--- a/lib/middleware/HandleAccessDeniedMiddleware.php
+++ b/lib/middleware/HandleAccessDeniedMiddleware.php
@@ -2,33 +2,25 @@
namespace Studip\Middleware;
use AccessDeniedException;
+use LoginException;
use Psr\Http\Message\ResponseInterface;
use Psr\Http\Message\ServerRequestInterface;
use Psr\Http\Server\MiddlewareInterface;
use Psr\Http\Server\RequestHandlerInterface;
-use Psr\Http\Message\ResponseFactoryInterface;
-use Request;
-use URLHelper;
+use User;
final class HandleAccessDeniedMiddleware implements MiddlewareInterface
{
- public function __construct(
- private readonly ResponseFactoryInterface $responseFactory
- ) {
- }
-
- /**
- * @SuppressWarnings(StaticAccess)
- * @SuppressWarnings(SuperGlobals)
- */
public function process(ServerRequestInterface $request, RequestHandlerInterface $handler): ResponseInterface
{
try {
return $handler->handle($request);
} catch (AccessDeniedException $ade) {
- $_SESSION['redirect_after_login'] ??= Request::url();
- return $this->responseFactory->createResponse(302)
- ->withHeader('Location', URLHelper::getURL('dispatch.php/login'));
+ if (!User::findCurrent()) {
+ throw new LoginException();
+ }
+
+ throw $ade;
}
}
}