提交 e00b07b9 编写于 作者: J James Edwards-Jones

JwtController avoids activating session checks

This used without a session and issues a sessionless token, so we
should avoid causing access checks based on the session.
上级 9f6ff5dc
# frozen_string_literal: true
class JwtController < ApplicationController
skip_around_action :set_session_storage
skip_before_action :authenticate_user!
skip_before_action :verify_authenticity_token
before_action :authenticate_project_or_user
......
......@@ -108,6 +108,14 @@ describe JwtController do
end
end
end
it 'does not cause session based checks to be activated' do
expect(Gitlab::Session).not_to receive(:with_session)
get '/jwt/auth', params: parameters, headers: headers
expect(response).to have_gitlab_http_status(200)
end
end
context 'using invalid login' do
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册