mirror of
https://github.com/filebrowser/filebrowser.git
synced 2026-01-23 02:35:10 +00:00
fix: disable cookie auth for non GET requests
This commit is contained in:
parent
cb43770025
commit
80030dee32
1 changed files with 5 additions and 3 deletions
|
|
@ -53,9 +53,11 @@ func (e extractor) ExtractToken(r *http.Request) (string, error) {
|
|||
return auth, nil
|
||||
}
|
||||
|
||||
cookie, _ := r.Cookie("auth")
|
||||
if cookie != nil && strings.Count(cookie.Value, ".") == 2 {
|
||||
return cookie.Value, nil
|
||||
if r.Method == http.MethodGet {
|
||||
cookie, _ := r.Cookie("auth")
|
||||
if cookie != nil && strings.Count(cookie.Value, ".") == 2 {
|
||||
return cookie.Value, nil
|
||||
}
|
||||
}
|
||||
|
||||
return "", request.ErrNoTokenInRequest
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue