diff --git a/front/php/templates/header.php b/front/php/templates/header.php index f4a5791c..8e305449 100755 --- a/front/php/templates/header.php +++ b/front/php/templates/header.php @@ -255,25 +255,25 @@ diff --git a/server/graphql_server/graphql_server_start.py b/server/graphql_server/graphql_server_start.py index a55b64a6..1ad89563 100755 --- a/server/graphql_server/graphql_server_start.py +++ b/server/graphql_server/graphql_server_start.py @@ -17,14 +17,16 @@ app = Flask(__name__) # Retrieve API token and port graphql_port_value = get_setting_value("GRAPHQL_PORT") -api_token_value = get_setting_value("API_TOKEN") + # Endpoint for GraphQL queries @app.route("/graphql", methods=["POST"]) def graphql_endpoint(): # Check for API token in headers - token = request.headers.get("Authorization") - if token != f"Bearer {api_token_value}": + incoming_header_token = request.headers.get("Authorization") + api_token_value = get_setting_value("API_TOKEN") + + if incoming_header_token != f"Bearer {api_token_value}": mylog('verbose', [f'[graphql_server] Unauthorized access attempt']) return jsonify({"error": "Unauthorized"}), 401