Fix API status editing: use auth:api guard

StatusEditController's constructor applies the web `auth` guard, which
Bearer/OAuth clients cannot satisfy. PUT /api/v1/statuses/{id} and
GET /api/v1/statuses/{id}/history therefore fail for every third-party
API client, while status create/delete keep working because
ApiV1Controller has no controller-level web auth.

The controller is routed only from routes/api.php, where the route group
already applies ['auth:api', 'validemail'], so no web/session route
depends on the old guard. Switch the constructor to match.
pull/6663/head
vinzgreg 2 months ago
parent 0f781cba34
commit d19671a92c

@ -15,7 +15,7 @@ class StatusEditController extends Controller
{
public function __construct()
{
$this->middleware('auth');
$this->middleware('auth:api');
abort_if(! config('exp.pue'), 404, 'Post editing is not enabled on this server.');
}

Loading…
Cancel
Save