Open Layers 3 WMS authentication

Viewed 1413

I have a GeoServer and would like to only provide layers via WMS to a user who has a user account. This is ok to set up on the GeoServer side in that you can enable Basic Authentication and then pass the credentials as part of the URL.

This works fine in Firefox, unfortunately this ability has been removed for many browsers now, as basic authentication is deprecated in the URL.

So setting a URL with:

https://MY_USER_NAME:MY_PASSWORD@www.BLAH.com

No longer works.

So I am left scratching my head as to how to provide credentials on the client side when making an OL3 WMS request. There appears to be a lack of documentation on this.

Typically my WMS calls look like this:

WMS_layer = new ol.layer.Tile({
      preload: Infinity,
      visible: true,
      opacity:0.7,
      extent: ol.proj.transformExtent([-1.194, 51.880, -1.111, 51.930], "EPSG:4326", "EPSG:3857"),
      source: new ol.source.TileWMS(({
        url: 'https://www.my-geoserver.co.uk/geoserver/' + workspace + '/wms',
        params: {'LAYERS': workspace + ':' + layer_name, 'TILED': true, 'VERSION': '1.3.0'},
        projection: projection,
        serverType: 'geoserver',
        FORMAT: 'image/jpeg'
        }))
});

So, as I can no longer add user name and password to the URL, how can I pass the authentication across. I can use authentication headers as one solution, but how can I send an authentication header via the WMS call within OL3?

I've heard mention that people tend to use a Proxy on the server side to handle the XHR request, I have no idea where to start with this either!

0 Answers
Related