fix: email confirmation link panic in API mode#371
Open
wythers wants to merge 1 commit intoaarondl:masterfrom
Open
fix: email confirmation link panic in API mode#371wythers wants to merge 1 commit intoaarondl:masterfrom
wythers wants to merge 1 commit intoaarondl:masterfrom
Conversation
When authboss is used as API server (ReadJSON=true), users clicking confirmation links from emails would cause panic and fail to confirm their accounts. This is because the code tries to read JSON body from GET requests used by confirmation links. The fix ensures confirmation links work properly in API mode
Owner
|
Surprised this didn't get found until now. Though maybe a better fix is to ignore json body in While it's true the spec doesn't forbid |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When authboss is used as API server (ReadJSON=true), users clicking confirmation links from emails would cause panic and fail to confirm their account. This is because the code tries to read JSON body from GET requests used by confirmation links.
The fix ensures confirmation links work properly in API mode