mirror of https://github.com/pixelfed/pixelfed
dev
staging
feature/configurable-min-registration-age
configcache-clean-rebased
l10n_crowdin_translations
dockerfile-compile-ffmpeg-x264-x265
fix/media-storage-optimized-charge
fix/dm-remote-delete-media-leak
feat/emoji-cloud-storage-v2
feat/story-cloud-storage-v2
fix/hashtags-outside-bmp
copilot/review-old-issues
groups
vue3
v0.1.9
v0.10.0
v0.10.1
v0.10.10
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.11.1
v0.11.10
v0.11.11
v0.11.12
v0.11.13
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.11.6
v0.11.7
v0.11.8
v0.11.9
v0.12.0
v0.12.1
v0.12.10
v0.12.11
v0.12.12
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.12.7
v0.12.8
v0.12.9
v0.13.0
v0.14.0
v0.14.1
v0.14.2
v0.14.3
v0.5.9
v0.6.0
v0.6.1
v0.7.6
v0.8.0
v0.8.5
v0.8.6
v0.9.0
v0.9.4
v0.9.5
v0.9.6
${ noResults }
1 Commits (822e9c98cb67be107ade2cfa4fd214ab2bf298a3)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
822e9c98cb |
Fix OAuth scope bypass on remove_from_followers endpoint
Fixes #6643 The POST /api/v1/accounts/{id}/remove_from_followers endpoint was missing the token existence check (! $request->user()->token()). While the tokenCan('follow') scope check was already present, the missing token guard meant unauthenticated token-less requests could potentially bypass the scope enforcement. Added the standard guard pattern consistent with accountFollowById and accountUnfollowById endpoints. Also adds tests verifying: - Read-only tokens are denied (403) - Follow-scoped tokens succeed (200) - Unauthenticated requests are denied (403) |
4 weeks ago |