{"id":4501153,"date":"2014-01-14T09:25:48","date_gmt":"2014-01-14T09:25:48","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/authentication-hacks\/"},"modified":"2016-08-21T14:44:28","modified_gmt":"2016-08-21T14:44:28","slug":"authentication-hacks","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/authentication-hacks\/","title":{"rendered":"Authentication hacks"},"content":{"rendered":"<p>In wp-json-server.php ,line 98, method check_authentication; You create a hook that allows custom authentication, however you do not allow for a fail safe from that hook.  The method only checks to see if a successful login is returned.  If not, it goes on to check the basic authentication.  I don&#8217;t know if I&#8217;m off here, but if some felt that basic authentication was unsafe and did not want it to be available at all, they cannot currently prevent access attempts of this nature.  Failure of login only allows for test of basic auth.  You may want to consider checking for null or some other fail value to return false and discontinue execution of the remainder of the method.<\/p>\n<p>https:\/\/wordpress.org\/plugins\/json-rest-api\/<\/p>\n","protected":false},"template":"","class_list":["post-4501153","topic","type-topic","status-closed","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/4501153","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/4501153\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=4501153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}