From 8da1a0e8d2f17df655c494ddf12b5753ece7eae3 Mon Sep 17 00:00:00 2001 From: Jack Hay Date: Thu, 11 Jan 2024 20:57:58 -0500 Subject: [PATCH] Require token for GET subscription endpoint (#28765) Fixes #28756 ## Changes - Require and check API token for `GET /repos/{owner}/{repo}/subscription` in order to populate `ctx.Doer`. --- routers/api/v1/api.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/routers/api/v1/api.go b/routers/api/v1/api.go index 09fde1e05b90..8dba0a79081a 100644 --- a/routers/api/v1/api.go +++ b/routers/api/v1/api.go @@ -1143,9 +1143,9 @@ func Routes() *web.Route { m.Get("/subscribers", repo.ListSubscribers) m.Group("/subscription", func() { m.Get("", user.IsWatching) - m.Put("", reqToken(), user.Watch) - m.Delete("", reqToken(), user.Unwatch) - }) + m.Put("", user.Watch) + m.Delete("", user.Unwatch) + }, reqToken()) m.Group("/releases", func() { m.Combo("").Get(repo.ListReleases). Post(reqToken(), reqRepoWriter(unit.TypeReleases), context.ReferencesGitRepo(), bind(api.CreateReleaseOption{}), repo.CreateRelease)