瀏覽代碼

check for token before session

Alexander Belanger 4 年之前
父節點
當前提交
50700793ea
共有 1 個文件被更改,包括 6 次插入6 次删除
  1. 6 6
      server/api/user_handler.go

+ 6 - 6
server/api/user_handler.go

@@ -838,12 +838,6 @@ func (app *App) sendUser(w http.ResponseWriter, userID uint, email string, email
 }
 
 func (app *App) getUserIDFromRequest(r *http.Request) (uint, error) {
-	session, err := app.Store.Get(r, app.ServerConf.CookieName)
-
-	if err != nil {
-		return 0, err
-	}
-
 	// first, check for token
 	tok := app.getTokenFromRequest(r)
 
@@ -851,6 +845,12 @@ func (app *App) getUserIDFromRequest(r *http.Request) (uint, error) {
 		return tok.IBy, nil
 	}
 
+	session, err := app.Store.Get(r, app.ServerConf.CookieName)
+
+	if err != nil {
+		return 0, err
+	}
+
 	userID, _ := session.Values["user_id"].(uint)
 
 	return userID, nil