Fix some user-independent endpoints potentially reading session cookies (#24650)
This commit is contained in:
parent
276c39361b
commit
1419f90ef2
6 changed files with 32 additions and 0 deletions
|
@ -2,9 +2,15 @@
|
|||
|
||||
class Api::V1::InstancesController < Api::BaseController
|
||||
skip_before_action :require_authenticated_user!, unless: :whitelist_mode?
|
||||
skip_around_action :set_locale
|
||||
|
||||
vary_by ''
|
||||
|
||||
# Override `current_user` to avoid reading session cookies unless in whitelist mode
|
||||
def current_user
|
||||
super if whitelist_mode?
|
||||
end
|
||||
|
||||
def show
|
||||
cache_even_if_authenticated!
|
||||
render_with_cache json: InstancePresenter.new, serializer: REST::V1::InstanceSerializer, root: 'instance'
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue