From d19671a92c01fcc8151dc3723736a928eb73d1c3 Mon Sep 17 00:00:00 2001 From: vinzgreg Date: Sat, 1 Aug 2026 09:34:16 +0200 Subject: [PATCH] Fix API status editing: use auth:api guard StatusEditController's constructor applies the web `auth` guard, which Bearer/OAuth clients cannot satisfy. PUT /api/v1/statuses/{id} and GET /api/v1/statuses/{id}/history therefore fail for every third-party API client, while status create/delete keep working because ApiV1Controller has no controller-level web auth. The controller is routed only from routes/api.php, where the route group already applies ['auth:api', 'validemail'], so no web/session route depends on the old guard. Switch the constructor to match. --- app/Http/Controllers/StatusEditController.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/Http/Controllers/StatusEditController.php b/app/Http/Controllers/StatusEditController.php index 168e21657..fab677115 100644 --- a/app/Http/Controllers/StatusEditController.php +++ b/app/Http/Controllers/StatusEditController.php @@ -15,7 +15,7 @@ class StatusEditController extends Controller { public function __construct() { - $this->middleware('auth'); + $this->middleware('auth:api'); abort_if(! config('exp.pue'), 404, 'Post editing is not enabled on this server.'); }