No auth check in UserController.feed_redirect/2, even on non-federating instances.
authorIvan Tashkinov <ivantashkinov@gmail.com>
Thu, 1 Oct 2020 18:41:22 +0000 (21:41 +0300)
committerIvan Tashkinov <ivantashkinov@gmail.com>
Thu, 1 Oct 2020 18:41:22 +0000 (21:41 +0300)
lib/pleroma/web/feed/user_controller.ex

index 71eb1ea7ee28ae207e73b6edcb1368232f8d203d..09ecdedb4c8700de2ff9ed5c4253c817f9d7fbc9 100644 (file)
@@ -23,12 +23,7 @@ defmodule Pleroma.Web.Feed.UserController do
 
   def feed_redirect(%{assigns: %{format: format}} = conn, _params)
       when format in ["json", "activity+json"] do
-    with %{halted: false} = conn <-
-           Pleroma.Plugs.EnsureAuthenticatedPlug.call(conn,
-             unless_func: &Pleroma.Web.FederatingPlug.federating?/1
-           ) do
-      ActivityPubController.call(conn, :user)
-    end
+    ActivityPubController.call(conn, :user)
   end
 
   def feed_redirect(conn, %{"nickname" => nickname}) do