mirror of
https://github.com/luckfox-eng29/kvm.git
synced 2026-01-18 03:28:19 +01:00
Don't allow empty tokens (#13)
This commit is contained in:
2
web.go
2
web.go
@@ -192,7 +192,7 @@ func protectedMiddleware() gin.HandlerFunc {
|
|||||||
}
|
}
|
||||||
|
|
||||||
authToken, err := c.Cookie("authToken")
|
authToken, err := c.Cookie("authToken")
|
||||||
if err != nil || authToken != config.LocalAuthToken {
|
if err != nil || authToken != config.LocalAuthToken || authToken == "" {
|
||||||
c.JSON(http.StatusUnauthorized, gin.H{"error": "Unauthorized"})
|
c.JSON(http.StatusUnauthorized, gin.H{"error": "Unauthorized"})
|
||||||
c.Abort()
|
c.Abort()
|
||||||
return
|
return
|
||||||
|
|||||||
Reference in New Issue
Block a user