mirror of
https://codeberg.org/PostERG/xamxam.git
synced 2026-05-06 11:09:18 +02:00
Fix 403 on HTMX fragment requests: AdminAuth Basic Auth sets session key
This commit is contained in:
4
TODO.md
4
TODO.md
@@ -52,6 +52,10 @@
|
||||
- [x] `admin/account.php` — admin password `confirm()` kept with `TODO` comment
|
||||
- [x] `admin.css` — added `.admin-dialog--sm`, `.admin-dialog__alert`, `.admin-dialog__footer` styles
|
||||
|
||||
## Fix 403 on HTMX tab requests in parametres.php
|
||||
- [x] `AdminAuth::requireLogin()` — now sets `$_SESSION[SESSION_KEY]` when accepting nginx Basic Auth credentials (was returning early without marking the session)
|
||||
- [x] `AdminAuth::isAuthenticated()` — now falls back to `PHP_AUTH_PW` verification (same logic as `requireLogin`) so HTMX requests to `system-fragment.php` authenticate even before a session exists
|
||||
|
||||
## Duplicate warning display fixes
|
||||
- [x] `toast-fragment.php` — 204 guard now also checks `warning`; warning was silently discarded before
|
||||
- [x] `partage/index.php` — warning stored as plain text (no pre-escaping); `htmlspecialchars()` applied once at render; was double-encoded before
|
||||
|
||||
Reference in New Issue
Block a user