]> git.openstreetmap.org Git - rails.git/blobdiff - app/controllers/api_controller.rb
Simplify deny_access handling
[rails.git] / app / controllers / api_controller.rb
index fb3717b2a981d99718e4a48b284ac2ac49175e25..8ddb7242fe5ee3a78d5188dfec62b6204eb5a653 100644 (file)
@@ -1,3 +1,17 @@
 class ApiController < ApplicationController
   skip_before_action :verify_authenticity_token
+
+  def deny_access(_exception)
+    if current_token
+      set_locale
+      report_error t("oauth.permissions.missing"), :forbidden
+    elsif current_user
+      head :forbidden
+    else
+      realm = "Web Password"
+      errormessage = "Couldn't authenticate you"
+      response.headers["WWW-Authenticate"] = "Basic realm=\"#{realm}\""
+      render :plain => errormessage, :status => :unauthorized
+    end
+  end
 end