mirror of
https://github.com/minetest/contentdb.git
synced 2025-01-10 23:17:37 +01:00
Fix access token being exposed after APIToken edit
This commit is contained in:
parent
53a5dffb26
commit
36615ef656
@ -80,14 +80,13 @@ def create_edit_token(username, id=None):
|
|||||||
token.owner = user
|
token.owner = user
|
||||||
token.access_token = randomString(32)
|
token.access_token = randomString(32)
|
||||||
|
|
||||||
|
# Store token so it can be shown in the edit page
|
||||||
|
session["token_" + str(token.id)] = token.access_token
|
||||||
|
|
||||||
form.populate_obj(token)
|
form.populate_obj(token)
|
||||||
db.session.add(token)
|
db.session.add(token)
|
||||||
|
|
||||||
db.session.commit() # save
|
db.session.commit() # save
|
||||||
|
|
||||||
# Store token so it can be shown in the edit page
|
|
||||||
session["token_" + str(token.id)] = token.access_token
|
|
||||||
|
|
||||||
return redirect(url_for("api.create_edit_token", username=username, id=token.id))
|
return redirect(url_for("api.create_edit_token", username=username, id=token.id))
|
||||||
|
|
||||||
return render_template("api/create_edit_token.html", user=user, form=form, token=token, access_token=access_token)
|
return render_template("api/create_edit_token.html", user=user, form=form, token=token, access_token=access_token)
|
||||||
|
Loading…
Reference in New Issue
Block a user