diff --git a/app/oauth.go b/app/oauth.go index a05fe1e947..ab419fcbeb 100644 --- a/app/oauth.go +++ b/app/oauth.go @@ -246,7 +246,7 @@ func (a *App) GetOAuthAccessTokenForCodeFlow(clientId, grantType, redirectUri, c var authData *model.AuthData result := <-a.Srv.Store.OAuth().GetAuthData(code) if result.Err != nil { - return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.expired_code.app_error", nil, "", http.StatusInternalServerError) + return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.expired_code.app_error", nil, "", http.StatusBadRequest) } authData = result.Data.(*model.AuthData) @@ -267,7 +267,7 @@ func (a *App) GetOAuthAccessTokenForCodeFlow(clientId, grantType, redirectUri, c result = <-a.Srv.Store.OAuth().GetPreviousAccessData(user.Id, clientId) if result.Err != nil { - return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.internal.app_error", nil, "", http.StatusInternalServerError) + return nil, model.NewAppError("GetOAuthAccessToken", "api.oauth.get_access_token.internal.app_error", nil, "", http.StatusBadRequest) } if result.Data != nil { diff --git a/web/handlers.go b/web/handlers.go index 71ad6af03e..cfc02650f0 100644 --- a/web/handlers.go +++ b/web/handlers.go @@ -195,7 +195,7 @@ func (h Handler) ServeHTTP(w http.ResponseWriter, r *http.Request) { c.Err.IsOAuth = false } - if IsApiCall(c.App, r) || IsWebhookCall(c.App, r) || len(r.Header.Get("X-Mobile-App")) > 0 { + if IsApiCall(c.App, r) || IsWebhookCall(c.App, r) || IsOAuthApiCall(c.App, r) || len(r.Header.Get("X-Mobile-App")) > 0 { w.WriteHeader(c.Err.StatusCode) w.Write([]byte(c.Err.ToJson())) } else { diff --git a/web/web.go b/web/web.go index 9e3e46ad19..1e1499c0d6 100644 --- a/web/web.go +++ b/web/web.go @@ -86,6 +86,21 @@ func IsWebhookCall(a *app.App, r *http.Request) bool { return strings.HasPrefix(r.URL.Path, path.Join(subpath, "hooks")+"/") } +func IsOAuthApiCall(config configservice.ConfigService, r *http.Request) bool { + subpath, _ := utils.GetSubpathFromConfig(config.Config()) + + if r.Method == "POST" && r.URL.Path == path.Join(subpath, "oauth", "authorize") { + return true + } + + if r.URL.Path == path.Join(subpath, "oauth", "apps", "authorized") || + r.URL.Path == path.Join(subpath, "oauth", "deauthorize") || + r.URL.Path == path.Join(subpath, "oauth", "access_token") { + return true + } + return false +} + func ReturnStatusOK(w http.ResponseWriter) { m := make(map[string]string) m[model.STATUS] = model.STATUS_OK