diff options
author | Jack Hay <jack@allspice.io> | 2024-01-11 20:57:58 -0500 |
---|---|---|
committer | GitHub <noreply@github.com> | 2024-01-12 01:57:58 +0000 |
commit | 7c2f093e856395cc118dcaa390b7a2234b8363f3 (patch) | |
tree | 59e7fdaa54f70fcc85cfcf6347b7e27eb03b58b0 | |
parent | 595a9291b6fadc02fa310d09abd5e01e942aa82c (diff) | |
download | gitea-7c2f093e856395cc118dcaa390b7a2234b8363f3.tar.gz gitea-7c2f093e856395cc118dcaa390b7a2234b8363f3.zip |
Require token for GET subscription endpoint (#28765)
Fixes #28756
## Changes
- Require and check API token for `GET
/repos/{owner}/{repo}/subscription` in order to populate `ctx.Doer`.
-rw-r--r-- | routers/api/v1/api.go | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/routers/api/v1/api.go b/routers/api/v1/api.go index 4fe4e20e79..8d7669762b 100644 --- a/routers/api/v1/api.go +++ b/routers/api/v1/api.go @@ -1156,9 +1156,9 @@ func Routes() *web.Route { m.Get("/subscribers", repo.ListSubscribers) m.Group("/subscription", func() { m.Get("", user.IsWatching) - m.Put("", reqToken(), user.Watch) - m.Delete("", reqToken(), user.Unwatch) - }) + m.Put("", user.Watch) + m.Delete("", user.Unwatch) + }, reqToken()) m.Group("/releases", func() { m.Combo("").Get(repo.ListReleases). Post(reqToken(), reqRepoWriter(unit.TypeReleases), context.ReferencesGitRepo(), bind(api.CreateReleaseOption{}), repo.CreateRelease) |