From 6d8ad1d754f080ca7aa13ccf92262cb5992ef4bd Mon Sep 17 00:00:00 2001 From: Andrea Mistrali Date: Fri, 26 Jul 2024 12:04:04 +0200 Subject: [PATCH] Only admins can inspect their token --- app/views/main.py | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/app/views/main.py b/app/views/main.py index 3cff275..1bc7d7f 100644 --- a/app/views/main.py +++ b/app/views/main.py @@ -38,9 +38,8 @@ def index(): @main_blueprint.route('/token', methods=['GET', 'POST']) -@auth.access_control('default') +@auth.authorize_admins('default') def token(): - print(auth.valid_access_token()) user_session = UserSession(session) # return jsonify(user_session.userinfo) return jsonify(access_token=user_session.access_token,