diff --git a/customerapi/controllers/RestController.php b/customerapi/controllers/RestController.php index e3faf1a..1b81dca 100644 --- a/customerapi/controllers/RestController.php +++ b/customerapi/controllers/RestController.php @@ -3,7 +3,6 @@ namespace customerapi\controllers; -use common\helpers\CorsCustom; use common\models\Customer; use Exception; use Lcobucci\JWT\Token; @@ -19,13 +18,20 @@ class RestController extends Controller public function behaviors() { $behaviors = parent::behaviors(); - $behaviors['authenticator'] = [ 'class' => JwtHttpBearerAuth::class, 'auth' => [$this, 'auth'], 'optional' => $this->getOptionalActions(), ]; - + $behaviors['corsFilter'] = [ + 'class' => Cors::class, + 'cors' => [ + // restrict access to + 'Origin' => ['https://botondfitness.hu'], + // Allow credentials (cookies, authorization headers, etc.) to be exposed to the browser + 'Access-Control-Allow-Credentials' => true, + ] + ]; return $behaviors; } @@ -44,7 +50,7 @@ class RestController extends Controller $customer = Customer::findOne(['id_customer' => $uid]); if (isset($customer)) { \Yii::$app->user->setIdentity($customer); - return $customer; + return $customer; } } catch (Exception $e) { Yii::error('Failed to load customer: ' . $e->getMessage()); @@ -62,3 +68,4 @@ class RestController extends Controller } +