Skip to content
Snippets Groups Projects

Add DPoP checks in GraphQL and API requests

Merged Ameya Darshan requested to merge ameya-dpop-2 into master
All threads resolved!
Compare and Show latest version
4 files
+ 52
11
Compare changes
  • Side-by-side
  • Inline
Files
4
@@ -158,6 +158,10 @@ def feature_category
private
def check_dpop!
# For unauthenticated requests we don't need DPoP checks
return unless current_user&.dpop_enabled
# For authenticated requests we check if the user has DPoP enabled
::Auth::DpopAuthenticationService.new(current_user: current_user,
personal_access_token_plaintext: get_personal_access_token,
request: current_request).execute
Loading