# CURL always bypass authentication issue

**URL:** <https://discourse.slimframework.com/t/curl-always-bypass-authentication-issue/4469>\
**Category:** Questions\
**Created:** [October 28, 2020, 3:45pm UTC](https://discourse.slimframework.com/t/curl-always-bypass-authentication-issue/4469 "2020-10-28T15:45:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gianghl1983](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/gianghl1983/32/1253_2.png) [@gianghl1983](https://discourse.slimframework.com/u/gianghl1983)\
**Post date:** [October 28, 2020, 3:45pm UTC](https://discourse.slimframework.com/t/curl-always-bypass-authentication-issue/4469/1 "2020-10-28T15:45:05Z")

</div>

Hi there,

I am new with Slim Framework, using JWT to protect my api. It helped me to protect, redirect to Auth page at [abc.com/auth](http://abc.com/auth). After login with correct username/password, a cookie will be set ($\_COOKIE[‘access\_token’]) and client can see the homepage’s content.

But with a CURL from another site set URL to ‘[abc.com](http://abc.com)’, all content of homepage’s shown (I call CURL from GUEST MODE, no cookie…).

This is my code, I hope someone can help me out ;)!

Br,

```
<?php
use Psr\Http\Message\ServerRequestInterface as Request;
use Psr\Http\Server\RequestHandlerInterface as RequestHandler;
use Slim\Psr7\Response;
use Selective\BasePath\BasePathMiddleware;
use Slim\App;
use Slim\Middleware\ErrorMiddleware;

return function (App $app) {
// Parse json, form data and xml
$app->addBodyParsingMiddleware();
	
	$app->add(function (Request $request, RequestHandler $handler) {
		$before = '';
		$response = $handler->handle($request);
		$uri = $request->getUri();
		
		if( !isset($_COOKIE['access_token']) && $uri->getPath() != '/auth' ){
			

			return $response->withHeader('Location', '/auth')->withStatus(302);
		}else{
			$token = $_COOKIE['access_token'];
			
		}
		$existingContent = (string) $response->getBody();

		$response = new Response();
		$response->getBody()->write($before . $existingContent);

		return $response;
	});
	$app->add(function ($request, $handler) {
		$response = $handler->handle($request);
		$response->getBody()->write('AFTER');
		return $response;
	});
// Add the Slim built-in routing middleware
$app->addRoutingMiddleware();
	
	$app->add(BasePathMiddleware::class); // <--- here

// Catch exceptions and errors
$app->add(ErrorMiddleware::class);
};
```

---

<div class="post-metadata">

**Author:** ![odan](https://avatars.discourse-cdn.com/v4/letter/o/9de053/32.png) [@odan](https://discourse.slimframework.com/u/odan)\
**Post date:** [October 28, 2020, 5:13pm UTC](https://discourse.slimframework.com/t/curl-always-bypass-authentication-issue/4469/2 "2020-10-28T17:13:13Z")

</div>

I think that cookies and JWT are conceptually contrary, because a JWT is stateless and a cookie are not stateless. So my question is why do you mix this two different concepts? Why don’t you use just cookies for the login and the session?

---

<div class="post-metadata">

**Author:** ![gianghl1983](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.slimframework.com/gianghl1983/32/1253_2.png) [@gianghl1983](https://discourse.slimframework.com/u/gianghl1983)\
**Post date:** [October 29, 2020, 5:05am UTC](https://discourse.slimframework.com/t/curl-always-bypass-authentication-issue/4469/3 "2020-10-29T05:05:29Z")

</div>

Thank you for reply! I am using both for 2 different purposes:  
1/ for Web user  
2/ for API call from Web App (and Mobile App…)

My teacher helped me to fix this with this modified code (hope help someone else…)

Br,

```
<?php

use Psr\Http\Message\ServerRequestInterface as Request;

use Psr\Http\Server\RequestHandlerInterface as RequestHandler;

use Slim\Psr7\Response;

use Selective\BasePath\BasePathMiddleware;

use Slim\App;

use Slim\Middleware\ErrorMiddleware;

return function (App $app) {

    // Parse json, form data and xml

    $app->addBodyParsingMiddleware();

    

    $app->add(function (Request $request, RequestHandler $handler) {

        $before = 'Before';

        $response = $handler->handle($request);

        $existingContent = (string) $response->getBody();

        $response = new Response();

        $uri = $request->getUri();

        

        if( !isset($_COOKIE['access_token']) && $uri->getPath() != '/auth' ){

            $response->getBody()->write('Redirect...');

            return $response->withHeader('Location', '/auth')->withStatus(302);

        }else{

            $token = $_COOKIE['access_token'];

            

        }

        $response->getBody()->write($before . $existingContent);

        return $response;

    });

    $app->add(function ($request, $handler) {

        $response = $handler->handle($request);

        $response->getBody()->write('AFTER');

        return $response;

    });

    // Add the Slim built-in routing middleware

    $app->addRoutingMiddleware();

    

    $app->add(BasePathMiddleware::class); // <--- here

    // Catch exceptions and errors

    $app->add(ErrorMiddleware::class);

};
```
