diff --git a/de/15.9/config/properties.po b/de/15.9/config/properties.po index 49a3b9c6..2a64dfe8 100644 --- a/de/15.9/config/properties.po +++ b/de/15.9/config/properties.po @@ -147,9 +147,6 @@ msgstr "" msgid "Length of API access token." msgstr "" -msgid "Whether API access token is required." -msgstr "" - msgid "API access token request parameter." msgstr "" diff --git a/de/15.9/config/properties.rst b/de/15.9/config/properties.rst index 5daf5b12..d81fbf36 100644 --- a/de/15.9/config/properties.rst +++ b/de/15.9/config/properties.rst @@ -290,9 +290,6 @@ Core * - api.access.token.length - Length of API access token. - ``60`` - * - api.access.token.required - - Whether API access token is required. - - ``false`` * - api.access.token.request.parameter - API access token request parameter. - (empty) diff --git a/de/15.9/install/upgrade.rst b/de/15.9/install/upgrade.rst index 2141f047..b9d7d99e 100644 --- a/de/15.9/install/upgrade.rst +++ b/de/15.9/install/upgrade.rst @@ -966,6 +966,21 @@ Namen verbliebener Wert wird nicht verwendet. Die Rollen ``admin-design`` und ``admin-design-view`` gewähren keine Rechte mehr. Ein Benutzer, der nur diese Rollen hat, gelangt nach der Anmeldung zur Suchoberfläche statt zur Verwaltungsoberfläche. +``api.access.token.required`` wurde entfernt +-------------------------------------------- + +``api.access.token.required`` gibt es in ``fess_config.properties`` nicht mehr. Ein unter diesem +Namen verbliebener Wert hat keine Wirkung, auch in einer aus 15.8 übernommenen +``fess_config.properties``. Mit ``true`` lehnte die Einstellung jede API-Anfrage eines nicht +angemeldeten Benutzers ab. Da die Suchoberfläche jetzt über ``/api/v2/search`` sucht, hätte sie +anonymen Benutzern zudem eine Suchoberfläche ohne Ergebnisse gezeigt. + +Eine Installation, die sie auf ``true`` gesetzt hatte, beantwortet API-Anfragen anonymer Benutzer +jetzt wie die Suchoberfläche mit den Gastrollen. Um anonyme Benutzer von der Suche auszuschließen, +setzen Sie ``login.required=true``. Zugriffstoken funktionieren wie bisher: Eine Anfrage mit einem +registrierten Zugriffstoken erhält dessen Berechtigungen, eine Anfrage mit einem nicht registrierten +oder abgelaufenen Token wird abgelehnt. + Migrationsaufgaben speziell für 15.9 ==================================== diff --git a/en/15.9/config/properties.rst b/en/15.9/config/properties.rst index 5daf5b12..d81fbf36 100644 --- a/en/15.9/config/properties.rst +++ b/en/15.9/config/properties.rst @@ -290,9 +290,6 @@ Core * - api.access.token.length - Length of API access token. - ``60`` - * - api.access.token.required - - Whether API access token is required. - - ``false`` * - api.access.token.request.parameter - API access token request parameter. - (empty) diff --git a/en/15.9/install/upgrade.rst b/en/15.9/install/upgrade.rst index ec56d4e8..2ae5a51c 100644 --- a/en/15.9/install/upgrade.rst +++ b/en/15.9/install/upgrade.rst @@ -930,6 +930,20 @@ names is not used. The ``admin-design`` and ``admin-design-view`` roles no longer grant anything. A user who has only these roles is taken to the search screen instead of the admin UI after logging in. +``api.access.token.required`` Was Removed +----------------------------------------- + +``api.access.token.required`` no longer exists in ``fess_config.properties``. A value left under +that name, including in a ``fess_config.properties`` carried over from 15.8, has no effect. With +``true`` it refused every API request from a user who was not logged in. Because the search screen +now searches through ``/api/v2/search``, it would also have left anonymous users with a search +screen that shows no results. + +An installation that set it to ``true`` now answers API requests from anonymous users with the +guest roles, as it does the search screen. To keep anonymous users from searching, set +``login.required=true``. Access tokens work as before: a request with a registered access token is +given the token's permissions, and a request with an unregistered or expired token is refused. + 15.9-Specific Migration Tasks ============================= diff --git a/es/15.9/config/properties.po b/es/15.9/config/properties.po index 49a3b9c6..2a64dfe8 100644 --- a/es/15.9/config/properties.po +++ b/es/15.9/config/properties.po @@ -147,9 +147,6 @@ msgstr "" msgid "Length of API access token." msgstr "" -msgid "Whether API access token is required." -msgstr "" - msgid "API access token request parameter." msgstr "" diff --git a/es/15.9/config/properties.rst b/es/15.9/config/properties.rst index 5daf5b12..d81fbf36 100644 --- a/es/15.9/config/properties.rst +++ b/es/15.9/config/properties.rst @@ -290,9 +290,6 @@ Core * - api.access.token.length - Length of API access token. - ``60`` - * - api.access.token.required - - Whether API access token is required. - - ``false`` * - api.access.token.request.parameter - API access token request parameter. - (empty) diff --git a/es/15.9/install/upgrade.rst b/es/15.9/install/upgrade.rst index c6eef58c..6bdcfad4 100644 --- a/es/15.9/install/upgrade.rst +++ b/es/15.9/install/upgrade.rst @@ -968,6 +968,21 @@ permanezca con estos nombres no se utiliza. Los roles ``admin-design`` y ``admin-design-view`` ya no otorgan ningún permiso. Un usuario que solo tenga estos roles llega a la pantalla de búsqueda, y no a la de administración, al iniciar sesión. +``api.access.token.required`` se ha eliminado +--------------------------------------------- + +``api.access.token.required`` ya no existe en ``fess_config.properties``. Un valor que permanezca con +ese nombre no tiene ningún efecto, incluso en un ``fess_config.properties`` conservado de la 15.8. +Con ``true``, rechazaba toda solicitud a la API de un usuario que no hubiera iniciado sesión. Como +la pantalla de búsqueda ahora busca a través de ``/api/v2/search``, además habría mostrado a los +usuarios anónimos una pantalla de búsqueda sin resultados. + +Una instalación que lo tenía en ``true`` responde ahora a las solicitudes a la API de usuarios +anónimos con los roles de invitado, igual que en la pantalla de búsqueda. Para impedir que los +usuarios anónimos busquen, establezca ``login.required=true``. Los tokens de acceso funcionan como +antes: una solicitud con un token de acceso registrado recibe los permisos de ese token, y una +solicitud con un token no registrado o caducado se rechaza. + Migración Específica de 15.9 ============================== diff --git a/fr/15.9/config/properties.po b/fr/15.9/config/properties.po index 49a3b9c6..2a64dfe8 100644 --- a/fr/15.9/config/properties.po +++ b/fr/15.9/config/properties.po @@ -147,9 +147,6 @@ msgstr "" msgid "Length of API access token." msgstr "" -msgid "Whether API access token is required." -msgstr "" - msgid "API access token request parameter." msgstr "" diff --git a/fr/15.9/config/properties.rst b/fr/15.9/config/properties.rst index 5daf5b12..d81fbf36 100644 --- a/fr/15.9/config/properties.rst +++ b/fr/15.9/config/properties.rst @@ -290,9 +290,6 @@ Core * - api.access.token.length - Length of API access token. - ``60`` - * - api.access.token.required - - Whether API access token is required. - - ``false`` * - api.access.token.request.parameter - API access token request parameter. - (empty) diff --git a/fr/15.9/install/upgrade.rst b/fr/15.9/install/upgrade.rst index 1dd372d3..165cfd7c 100644 --- a/fr/15.9/install/upgrade.rst +++ b/fr/15.9/install/upgrade.rst @@ -976,6 +976,21 @@ Les rôles ``admin-design`` et ``admin-design-view`` n'accordent plus aucun droi n'a que ces rôles arrive sur l'écran de recherche, et non sur l'écran d'administration, après s'être connecté. +``api.access.token.required`` a été supprimé +-------------------------------------------- + +``api.access.token.required`` n'existe plus dans ``fess_config.properties``. Une valeur laissée sous +ce nom n'a aucun effet, y compris dans un ``fess_config.properties`` repris de la 15.8. Avec +``true``, ce paramètre refusait toute requête API d'un utilisateur non connecté. Comme l'écran de +recherche effectue désormais ses recherches via ``/api/v2/search``, il aurait en outre présenté aux +utilisateurs anonymes un écran de recherche sans résultats. + +Une installation qui l'avait réglé sur ``true`` répond désormais aux requêtes API des utilisateurs +anonymes avec les rôles invités, comme pour l'écran de recherche. Pour empêcher les utilisateurs +anonymes de rechercher, définissez ``login.required=true``. Les jetons d'accès fonctionnent comme +avant : une requête munie d'un jeton d'accès enregistré reçoit les permissions de ce jeton, et une +requête munie d'un jeton non enregistré ou expiré est refusée. + Migrations spécifiques à la 15.9 ================================ diff --git a/ja/15.9/config/properties.po b/ja/15.9/config/properties.po index 49a3b9c6..2a64dfe8 100644 --- a/ja/15.9/config/properties.po +++ b/ja/15.9/config/properties.po @@ -147,9 +147,6 @@ msgstr "" msgid "Length of API access token." msgstr "" -msgid "Whether API access token is required." -msgstr "" - msgid "API access token request parameter." msgstr "" diff --git a/ja/15.9/config/properties.rst b/ja/15.9/config/properties.rst index 5daf5b12..d81fbf36 100644 --- a/ja/15.9/config/properties.rst +++ b/ja/15.9/config/properties.rst @@ -290,9 +290,6 @@ Core * - api.access.token.length - Length of API access token. - ``60`` - * - api.access.token.required - - Whether API access token is required. - - ``false`` * - api.access.token.request.parameter - API access token request parameter. - (empty) diff --git a/ja/15.9/install/upgrade.rst b/ja/15.9/install/upgrade.rst index 12ebbf0f..f2e63212 100644 --- a/ja/15.9/install/upgrade.rst +++ b/ja/15.9/install/upgrade.rst @@ -926,6 +926,20 @@ jcifs の既定値のままになります。 ``admin-design`` と ``admin-design-view`` のロールは、何の権限も与えなくなりました。これらのロールだけを 持つユーザーは、ログインすると管理画面ではなく検索画面に移動します。 +``api.access.token.required`` の削除 +------------------------------------ + +``api.access.token.required`` は ``fess_config.properties`` から削除されました。15.8 から引き継いだ +``fess_config.properties`` に残っている場合も含め、この名前の値は効果がありません。 ``true`` にすると、 +ログインしていないユーザーからの API リクエストをすべて拒否していました。検索画面は +``/api/v2/search`` を使って検索するようになったため、この設定では匿名ユーザーに結果のない検索画面が +表示されることにもなります。 + +``true`` に設定していた環境では、匿名ユーザーからの API リクエストにも、検索画面と同じくゲストのロールで +応答するようになります。匿名ユーザーに検索させない場合は ``login.required=true`` を設定してください。 +アクセストークンの動作は変わりません。登録済みのアクセストークンを付けたリクエストにはそのトークンの +権限が与えられ、未登録または期限切れのトークンを付けたリクエストは拒否されます。 + 15.9 固有の移行作業 =================== diff --git a/ko/15.9/config/properties.po b/ko/15.9/config/properties.po index 49a3b9c6..2a64dfe8 100644 --- a/ko/15.9/config/properties.po +++ b/ko/15.9/config/properties.po @@ -147,9 +147,6 @@ msgstr "" msgid "Length of API access token." msgstr "" -msgid "Whether API access token is required." -msgstr "" - msgid "API access token request parameter." msgstr "" diff --git a/ko/15.9/config/properties.rst b/ko/15.9/config/properties.rst index 5daf5b12..d81fbf36 100644 --- a/ko/15.9/config/properties.rst +++ b/ko/15.9/config/properties.rst @@ -290,9 +290,6 @@ Core * - api.access.token.length - Length of API access token. - ``60`` - * - api.access.token.required - - Whether API access token is required. - - ``false`` * - api.access.token.request.parameter - API access token request parameter. - (empty) diff --git a/ko/15.9/install/upgrade.rst b/ko/15.9/install/upgrade.rst index 05a8c4b8..7c5328cf 100644 --- a/ko/15.9/install/upgrade.rst +++ b/ko/15.9/install/upgrade.rst @@ -928,6 +928,19 @@ API 가 호출될 때 로그에 기록됩니다. JavaScript 를 실행하지 않 ``admin-design`` 과 ``admin-design-view`` 롤은 더 이상 아무 권한도 부여하지 않습니다. 이 롤만 가진 사용자는 로그인하면 관리 화면이 아니라 검색 화면으로 이동합니다. +``api.access.token.required`` 삭제 +---------------------------------- + +``api.access.token.required`` 는 ``fess_config.properties`` 에서 삭제되었습니다. 15.8 에서 가져온 +``fess_config.properties`` 에 남아 있는 경우를 포함하여, 이 이름의 값은 효과가 없습니다. ``true`` 로 +설정하면 로그인하지 않은 사용자의 API 요청을 모두 거부했습니다. 이제 검색 화면은 ``/api/v2/search`` 로 +검색하므로, 이 설정은 익명 사용자에게 결과가 없는 검색 화면을 보여 주게 됩니다. + +``true`` 로 설정했던 환경에서는 이제 익명 사용자의 API 요청에도 검색 화면과 마찬가지로 게스트 롤로 +응답합니다. 익명 사용자가 검색하지 못하게 하려면 ``login.required=true`` 를 설정하십시오. 액세스 토큰의 +동작은 변경되지 않았습니다. 등록된 액세스 토큰이 있는 요청에는 해당 토큰의 권한이 부여되고, 등록되지 +않았거나 만료된 토큰이 있는 요청은 거부됩니다. + 15.9 전용 마이그레이션 작업 =========================== diff --git a/zh-cn/15.9/config/properties.po b/zh-cn/15.9/config/properties.po index 49a3b9c6..2a64dfe8 100644 --- a/zh-cn/15.9/config/properties.po +++ b/zh-cn/15.9/config/properties.po @@ -147,9 +147,6 @@ msgstr "" msgid "Length of API access token." msgstr "" -msgid "Whether API access token is required." -msgstr "" - msgid "API access token request parameter." msgstr "" diff --git a/zh-cn/15.9/config/properties.rst b/zh-cn/15.9/config/properties.rst index 5daf5b12..d81fbf36 100644 --- a/zh-cn/15.9/config/properties.rst +++ b/zh-cn/15.9/config/properties.rst @@ -290,9 +290,6 @@ Core * - api.access.token.length - Length of API access token. - ``60`` - * - api.access.token.required - - Whether API access token is required. - - ``false`` * - api.access.token.request.parameter - API access token request parameter. - (empty) diff --git a/zh-cn/15.9/install/upgrade.rst b/zh-cn/15.9/install/upgrade.rst index b71c18bb..3536ca6a 100644 --- a/zh-cn/15.9/install/upgrade.rst +++ b/zh-cn/15.9/install/upgrade.rst @@ -884,6 +884,17 @@ SMB 爬取一直以 jcifs 的默认值运行。15.9 传递新名称: ``admin-design`` 和 ``admin-design-view`` 角色不再授予任何权限。仅拥有这些角色的用户登录后会进入 搜索界面,而不是管理界面。 +``api.access.token.required`` 已删除 +------------------------------------ + +``fess_config.properties`` 中已不存在 ``api.access.token.required`` 。以该名称保留的值不会生效, +包括从 15.8 沿用的 ``fess_config.properties`` 中的值。设置为 ``true`` 时,它会拒绝所有来自未登录用户的 +API 请求。由于搜索界面现在通过 ``/api/v2/search`` 进行搜索,该设置还会使匿名用户看到没有结果的搜索界面。 + +曾将其设置为 ``true`` 的环境,现在会像对待搜索界面一样,以访客角色响应匿名用户的 API 请求。 +如需禁止匿名用户搜索,请设置 ``login.required=true`` 。访问令牌的行为不变:带有已注册访问令牌的请求 +会获得该令牌的权限,带有未注册或已过期令牌的请求会被拒绝。 + 15.9 特有的迁移工作 ===================