Don't look for personal access tokens in the DB when the parameter/header is not passed.
This commit is contained in:
parent
05b319b0b4
commit
6d44433176
1 changed files with 1 additions and 1 deletions
|
@ -374,7 +374,7 @@ class ApplicationController < ActionController::Base
|
|||
|
||||
def get_user_from_personal_access_token
|
||||
token_string = params[:private_token].presence || request.headers['PRIVATE-TOKEN'].presence
|
||||
personal_access_token = PersonalAccessToken.active.find_by_token(token_string)
|
||||
personal_access_token = PersonalAccessToken.active.find_by_token(token_string) if token_string
|
||||
personal_access_token.user if personal_access_token
|
||||
end
|
||||
end
|
||||
|
|
Loading…
Reference in a new issue