You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
mastodon/app/controllers/api/v1/admin
Claire 62c6e12fa5
Fix admin API unconditionally requiring CSRF token (#17975)
Fixes #17898

Since #17204, the admin API has only been available through the web
application because of the unconditional requirement to provide a valid CSRF
token.

This commit changes it back to `null_session`, which should make it work
both with session-based authentication (provided a CSRF token) and with a
bearer token.
3 years ago
..
trends Fix admin API unconditionally requiring CSRF token (#17975) 3 years ago
account_actions_controller.rb Fix admin API unconditionally requiring CSRF token (#17975) 3 years ago
accounts_controller.rb Fix admin API unconditionally requiring CSRF token (#17975) 3 years ago
dimensions_controller.rb Fix admin API unconditionally requiring CSRF token (#17975) 3 years ago
measures_controller.rb Fix admin API unconditionally requiring CSRF token (#17975) 3 years ago
reports_controller.rb Fix admin API unconditionally requiring CSRF token (#17975) 3 years ago
retention_controller.rb Fix admin API unconditionally requiring CSRF token (#17975) 3 years ago