auth token

This commit is contained in:
andrey
2021-08-05 18:52:07 +03:00
parent 3222cf821d
commit e73ac5e5df
3 changed files with 23 additions and 11 deletions

View File

@ -5,6 +5,8 @@ namespace frontend\modules\api\controllers;
use common\behaviors\GsCors;
use common\models\Options;
use yii\filters\AccessControl;
use yii\filters\auth\CompositeAuth;
use yii\filters\auth\HttpBearerAuth;
use yii\filters\auth\QueryParamAuth;
class SkillsController extends \yii\rest\Controller
@ -18,10 +20,12 @@ class SkillsController extends \yii\rest\Controller
'application/json' => \yii\web\Response::FORMAT_JSON,
],
],
'authenticatior' => [
'class' => QueryParamAuth::class, //implement access token authentication
'except' => ['login'], // no need to verify the access token method, pay attention to distinguish between $noAclLogin
],
'authenticator' => [
'class' => CompositeAuth::class,
'authMethods' => [
HttpBearerAuth::class,
],
]
// 'corsFilter' => [
// 'class' => GsCors::class,
// 'cors' => [