Skip to content

Commit dcce15f

Browse files
committed
remove query.access_token
1 parent 39a31a2 commit dcce15f

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

core/middleware.js

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -74,16 +74,17 @@ middleware.checkToken = function(req, res, next) {
7474
var authType = 1;
7575
var authToken = null;
7676
if (_.eq(authArr[0], 'Bearer')) {
77-
authType = 1;
7877
authToken = authArr[1]; //Bearer
78+
if (authToken && authToken.length > 64) {
79+
authType = 2;
80+
} else {
81+
authType = 1;
82+
}
7983
} else if(_.eq(authArr[0], 'Basic')) {
8084
authType = 2;
8185
var b = new Buffer(authArr[1], 'base64');
8286
var user = _.split(b.toString(), ':');
8387
authToken = _.get(user, '1');
84-
} else {
85-
authType = 2;
86-
authToken = _.trim(_.trimStart(_.get(req, 'query.access_token', null)));
8788
}
8889
if (authToken && authType == 1) {
8990
checkAuthToken(authToken)

0 commit comments

Comments
 (0)