Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 0 additions & 3 deletions de/15.9/config/properties.po
Original file line number Diff line number Diff line change
Expand Up @@ -147,9 +147,6 @@ msgstr ""
msgid "Length of API access token."
msgstr ""

msgid "Whether API access token is required."
msgstr ""

msgid "API access token request parameter."
msgstr ""

Expand Down
3 changes: 0 additions & 3 deletions de/15.9/config/properties.rst
Original file line number Diff line number Diff line change
Expand Up @@ -290,9 +290,6 @@ Core
* - api.access.token.length
- Length of API access token.
- ``60``
* - api.access.token.required
- Whether API access token is required.
- ``false``
* - api.access.token.request.parameter
- API access token request parameter.
- (empty)
Expand Down
15 changes: 15 additions & 0 deletions de/15.9/install/upgrade.rst
Original file line number Diff line number Diff line change
Expand Up @@ -966,6 +966,21 @@ Namen verbliebener Wert wird nicht verwendet.
Die Rollen ``admin-design`` und ``admin-design-view`` gewähren keine Rechte mehr. Ein Benutzer, der
nur diese Rollen hat, gelangt nach der Anmeldung zur Suchoberfläche statt zur Verwaltungsoberfläche.

``api.access.token.required`` wurde entfernt
--------------------------------------------

``api.access.token.required`` gibt es in ``fess_config.properties`` nicht mehr. Ein unter diesem
Namen verbliebener Wert hat keine Wirkung, auch in einer aus 15.8 übernommenen
``fess_config.properties``. Mit ``true`` lehnte die Einstellung jede API-Anfrage eines nicht
angemeldeten Benutzers ab. Da die Suchoberfläche jetzt über ``/api/v2/search`` sucht, hätte sie
anonymen Benutzern zudem eine Suchoberfläche ohne Ergebnisse gezeigt.

Eine Installation, die sie auf ``true`` gesetzt hatte, beantwortet API-Anfragen anonymer Benutzer
jetzt wie die Suchoberfläche mit den Gastrollen. Um anonyme Benutzer von der Suche auszuschließen,
setzen Sie ``login.required=true``. Zugriffstoken funktionieren wie bisher: Eine Anfrage mit einem
registrierten Zugriffstoken erhält dessen Berechtigungen, eine Anfrage mit einem nicht registrierten
oder abgelaufenen Token wird abgelehnt.

Migrationsaufgaben speziell für 15.9
====================================

Expand Down
3 changes: 0 additions & 3 deletions en/15.9/config/properties.rst
Original file line number Diff line number Diff line change
Expand Up @@ -290,9 +290,6 @@ Core
* - api.access.token.length
- Length of API access token.
- ``60``
* - api.access.token.required
- Whether API access token is required.
- ``false``
* - api.access.token.request.parameter
- API access token request parameter.
- (empty)
Expand Down
14 changes: 14 additions & 0 deletions en/15.9/install/upgrade.rst
Original file line number Diff line number Diff line change
Expand Up @@ -930,6 +930,20 @@ names is not used.
The ``admin-design`` and ``admin-design-view`` roles no longer grant anything. A user who has only
these roles is taken to the search screen instead of the admin UI after logging in.

``api.access.token.required`` Was Removed
-----------------------------------------

``api.access.token.required`` no longer exists in ``fess_config.properties``. A value left under
that name, including in a ``fess_config.properties`` carried over from 15.8, has no effect. With
``true`` it refused every API request from a user who was not logged in. Because the search screen
now searches through ``/api/v2/search``, it would also have left anonymous users with a search
screen that shows no results.

An installation that set it to ``true`` now answers API requests from anonymous users with the
guest roles, as it does the search screen. To keep anonymous users from searching, set
``login.required=true``. Access tokens work as before: a request with a registered access token is
given the token's permissions, and a request with an unregistered or expired token is refused.

15.9-Specific Migration Tasks
=============================

Expand Down
3 changes: 0 additions & 3 deletions es/15.9/config/properties.po
Original file line number Diff line number Diff line change
Expand Up @@ -147,9 +147,6 @@ msgstr ""
msgid "Length of API access token."
msgstr ""

msgid "Whether API access token is required."
msgstr ""

msgid "API access token request parameter."
msgstr ""

Expand Down
3 changes: 0 additions & 3 deletions es/15.9/config/properties.rst
Original file line number Diff line number Diff line change
Expand Up @@ -290,9 +290,6 @@ Core
* - api.access.token.length
- Length of API access token.
- ``60``
* - api.access.token.required
- Whether API access token is required.
- ``false``
* - api.access.token.request.parameter
- API access token request parameter.
- (empty)
Expand Down
15 changes: 15 additions & 0 deletions es/15.9/install/upgrade.rst
Original file line number Diff line number Diff line change
Expand Up @@ -968,6 +968,21 @@ permanezca con estos nombres no se utiliza.
Los roles ``admin-design`` y ``admin-design-view`` ya no otorgan ningún permiso. Un usuario que solo
tenga estos roles llega a la pantalla de búsqueda, y no a la de administración, al iniciar sesión.

``api.access.token.required`` se ha eliminado
---------------------------------------------

``api.access.token.required`` ya no existe en ``fess_config.properties``. Un valor que permanezca con
ese nombre no tiene ningún efecto, incluso en un ``fess_config.properties`` conservado de la 15.8.
Con ``true``, rechazaba toda solicitud a la API de un usuario que no hubiera iniciado sesión. Como
la pantalla de búsqueda ahora busca a través de ``/api/v2/search``, además habría mostrado a los
usuarios anónimos una pantalla de búsqueda sin resultados.

Una instalación que lo tenía en ``true`` responde ahora a las solicitudes a la API de usuarios
anónimos con los roles de invitado, igual que en la pantalla de búsqueda. Para impedir que los
usuarios anónimos busquen, establezca ``login.required=true``. Los tokens de acceso funcionan como
antes: una solicitud con un token de acceso registrado recibe los permisos de ese token, y una
solicitud con un token no registrado o caducado se rechaza.

Migración Específica de 15.9
==============================

Expand Down
3 changes: 0 additions & 3 deletions fr/15.9/config/properties.po
Original file line number Diff line number Diff line change
Expand Up @@ -147,9 +147,6 @@ msgstr ""
msgid "Length of API access token."
msgstr ""

msgid "Whether API access token is required."
msgstr ""

msgid "API access token request parameter."
msgstr ""

Expand Down
3 changes: 0 additions & 3 deletions fr/15.9/config/properties.rst
Original file line number Diff line number Diff line change
Expand Up @@ -290,9 +290,6 @@ Core
* - api.access.token.length
- Length of API access token.
- ``60``
* - api.access.token.required
- Whether API access token is required.
- ``false``
* - api.access.token.request.parameter
- API access token request parameter.
- (empty)
Expand Down
15 changes: 15 additions & 0 deletions fr/15.9/install/upgrade.rst
Original file line number Diff line number Diff line change
Expand Up @@ -976,6 +976,21 @@ Les rôles ``admin-design`` et ``admin-design-view`` n'accordent plus aucun droi
n'a que ces rôles arrive sur l'écran de recherche, et non sur l'écran d'administration, après
s'être connecté.

``api.access.token.required`` a été supprimé
--------------------------------------------

``api.access.token.required`` n'existe plus dans ``fess_config.properties``. Une valeur laissée sous
ce nom n'a aucun effet, y compris dans un ``fess_config.properties`` repris de la 15.8. Avec
``true``, ce paramètre refusait toute requête API d'un utilisateur non connecté. Comme l'écran de
recherche effectue désormais ses recherches via ``/api/v2/search``, il aurait en outre présenté aux
utilisateurs anonymes un écran de recherche sans résultats.

Une installation qui l'avait réglé sur ``true`` répond désormais aux requêtes API des utilisateurs
anonymes avec les rôles invités, comme pour l'écran de recherche. Pour empêcher les utilisateurs
anonymes de rechercher, définissez ``login.required=true``. Les jetons d'accès fonctionnent comme
avant : une requête munie d'un jeton d'accès enregistré reçoit les permissions de ce jeton, et une
requête munie d'un jeton non enregistré ou expiré est refusée.

Migrations spécifiques à la 15.9
================================

Expand Down
3 changes: 0 additions & 3 deletions ja/15.9/config/properties.po
Original file line number Diff line number Diff line change
Expand Up @@ -147,9 +147,6 @@ msgstr ""
msgid "Length of API access token."
msgstr ""

msgid "Whether API access token is required."
msgstr ""

msgid "API access token request parameter."
msgstr ""

Expand Down
3 changes: 0 additions & 3 deletions ja/15.9/config/properties.rst
Original file line number Diff line number Diff line change
Expand Up @@ -290,9 +290,6 @@ Core
* - api.access.token.length
- Length of API access token.
- ``60``
* - api.access.token.required
- Whether API access token is required.
- ``false``
* - api.access.token.request.parameter
- API access token request parameter.
- (empty)
Expand Down
14 changes: 14 additions & 0 deletions ja/15.9/install/upgrade.rst
Original file line number Diff line number Diff line change
Expand Up @@ -926,6 +926,20 @@ jcifs の既定値のままになります。
``admin-design`` と ``admin-design-view`` のロールは、何の権限も与えなくなりました。これらのロールだけを
持つユーザーは、ログインすると管理画面ではなく検索画面に移動します。

``api.access.token.required`` の削除
------------------------------------

``api.access.token.required`` は ``fess_config.properties`` から削除されました。15.8 から引き継いだ
``fess_config.properties`` に残っている場合も含め、この名前の値は効果がありません。 ``true`` にすると、
ログインしていないユーザーからの API リクエストをすべて拒否していました。検索画面は
``/api/v2/search`` を使って検索するようになったため、この設定では匿名ユーザーに結果のない検索画面が
表示されることにもなります。

``true`` に設定していた環境では、匿名ユーザーからの API リクエストにも、検索画面と同じくゲストのロールで
応答するようになります。匿名ユーザーに検索させない場合は ``login.required=true`` を設定してください。
アクセストークンの動作は変わりません。登録済みのアクセストークンを付けたリクエストにはそのトークンの
権限が与えられ、未登録または期限切れのトークンを付けたリクエストは拒否されます。

15.9 固有の移行作業
===================

Expand Down
3 changes: 0 additions & 3 deletions ko/15.9/config/properties.po
Original file line number Diff line number Diff line change
Expand Up @@ -147,9 +147,6 @@ msgstr ""
msgid "Length of API access token."
msgstr ""

msgid "Whether API access token is required."
msgstr ""

msgid "API access token request parameter."
msgstr ""

Expand Down
3 changes: 0 additions & 3 deletions ko/15.9/config/properties.rst
Original file line number Diff line number Diff line change
Expand Up @@ -290,9 +290,6 @@ Core
* - api.access.token.length
- Length of API access token.
- ``60``
* - api.access.token.required
- Whether API access token is required.
- ``false``
* - api.access.token.request.parameter
- API access token request parameter.
- (empty)
Expand Down
13 changes: 13 additions & 0 deletions ko/15.9/install/upgrade.rst
Original file line number Diff line number Diff line change
Expand Up @@ -928,6 +928,19 @@ API 가 호출될 때 로그에 기록됩니다. JavaScript 를 실행하지 않
``admin-design`` 과 ``admin-design-view`` 롤은 더 이상 아무 권한도 부여하지 않습니다. 이 롤만 가진
사용자는 로그인하면 관리 화면이 아니라 검색 화면으로 이동합니다.

``api.access.token.required`` 삭제
----------------------------------

``api.access.token.required`` 는 ``fess_config.properties`` 에서 삭제되었습니다. 15.8 에서 가져온
``fess_config.properties`` 에 남아 있는 경우를 포함하여, 이 이름의 값은 효과가 없습니다. ``true`` 로
설정하면 로그인하지 않은 사용자의 API 요청을 모두 거부했습니다. 이제 검색 화면은 ``/api/v2/search`` 로
검색하므로, 이 설정은 익명 사용자에게 결과가 없는 검색 화면을 보여 주게 됩니다.

``true`` 로 설정했던 환경에서는 이제 익명 사용자의 API 요청에도 검색 화면과 마찬가지로 게스트 롤로
응답합니다. 익명 사용자가 검색하지 못하게 하려면 ``login.required=true`` 를 설정하십시오. 액세스 토큰의
동작은 변경되지 않았습니다. 등록된 액세스 토큰이 있는 요청에는 해당 토큰의 권한이 부여되고, 등록되지
않았거나 만료된 토큰이 있는 요청은 거부됩니다.

15.9 전용 마이그레이션 작업
===========================

Expand Down
3 changes: 0 additions & 3 deletions zh-cn/15.9/config/properties.po
Original file line number Diff line number Diff line change
Expand Up @@ -147,9 +147,6 @@ msgstr ""
msgid "Length of API access token."
msgstr ""

msgid "Whether API access token is required."
msgstr ""

msgid "API access token request parameter."
msgstr ""

Expand Down
3 changes: 0 additions & 3 deletions zh-cn/15.9/config/properties.rst
Original file line number Diff line number Diff line change
Expand Up @@ -290,9 +290,6 @@ Core
* - api.access.token.length
- Length of API access token.
- ``60``
* - api.access.token.required
- Whether API access token is required.
- ``false``
* - api.access.token.request.parameter
- API access token request parameter.
- (empty)
Expand Down
11 changes: 11 additions & 0 deletions zh-cn/15.9/install/upgrade.rst
Original file line number Diff line number Diff line change
Expand Up @@ -884,6 +884,17 @@ SMB 爬取一直以 jcifs 的默认值运行。15.9 传递新名称:
``admin-design`` 和 ``admin-design-view`` 角色不再授予任何权限。仅拥有这些角色的用户登录后会进入
搜索界面,而不是管理界面。

``api.access.token.required`` 已删除
------------------------------------

``fess_config.properties`` 中已不存在 ``api.access.token.required`` 。以该名称保留的值不会生效,
包括从 15.8 沿用的 ``fess_config.properties`` 中的值。设置为 ``true`` 时,它会拒绝所有来自未登录用户的
API 请求。由于搜索界面现在通过 ``/api/v2/search`` 进行搜索,该设置还会使匿名用户看到没有结果的搜索界面。

曾将其设置为 ``true`` 的环境,现在会像对待搜索界面一样,以访客角色响应匿名用户的 API 请求。
如需禁止匿名用户搜索,请设置 ``login.required=true`` 。访问令牌的行为不变:带有已注册访问令牌的请求
会获得该令牌的权限,带有未注册或已过期令牌的请求会被拒绝。

15.9 特有的迁移工作
===================

Expand Down
Loading