unit Auth.HttpServer;
interface
procedure RegisterBearerAuthHttpServer;
implementation
uses
SysUtils, InContext, IW.Server.HTTPIndy, IW.Server.Indy;
type
TBearerAwareHttpServerIndy = class(THTTPServerIndy)
private
procedure HandleParseAuthentication(AContext: TInContext; const AAuthType, AAuthData: string;
var VUsername, VPassword: string; var VHandled: Boolean);
protected
procedure InitComponent; override;
end;
procedure TBearerAwareHttpServerIndy.InitComponent;
begin
inherited;
OnParseAuthentication := HandleParseAuthentication;
end;
procedure TBearerAwareHttpServerIndy.HandleParseAuthentication(AContext: TInContext;
const AAuthType, AAuthData: string; var VUsername, VPassword: string; var VHandled: Boolean);
begin
// validation of the token is done in the contenthandler
// here is accepting the scheme sufficient
VHandled := SameText(AAuthType, 'Bearer');
end;
procedure RegisterBearerAuthHttpServer;
begin
TSaServerIndy.RegisterHttpServerIndy(TBearerAwareHttpServerIndy);
end;
end.