Feature: Allow token introspection without read scope (#27142)
This commit is contained in:
		
					parent
					
						
							
								4612576c68
							
						
					
				
			
			
				commit
				
					
						7c3fea7275
					
				
			
		
					 3 changed files with 79 additions and 6 deletions
				
			
		|  | @ -1,9 +1,9 @@ | |||
| # frozen_string_literal: true | ||||
| 
 | ||||
| class Api::V1::Apps::CredentialsController < Api::BaseController | ||||
|   before_action -> { doorkeeper_authorize! :read } | ||||
| 
 | ||||
|   def show | ||||
|     render json: doorkeeper_token.application, serializer: REST::ApplicationSerializer, fields: %i(name website vapid_key) | ||||
|     return doorkeeper_render_error unless valid_doorkeeper_token? | ||||
| 
 | ||||
|     render json: doorkeeper_token.application, serializer: REST::ApplicationSerializer, fields: %i(name website vapid_key client_id scopes) | ||||
|   end | ||||
| end | ||||
|  |  | |||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue