mirror of
https://mau.dev/maunium/synapse.git
synced 2024-11-10 12:02:43 +01:00
Merge pull request #2591 from matrix-org/rav/device_delete_auth
Device deletion: check UI auth matches access token
This commit is contained in:
commit
4d83632009
1 changed files with 8 additions and 5 deletions
|
@ -117,6 +117,8 @@ class DeviceRestServlet(servlet.RestServlet):
|
||||||
|
|
||||||
@defer.inlineCallbacks
|
@defer.inlineCallbacks
|
||||||
def on_DELETE(self, request, device_id):
|
def on_DELETE(self, request, device_id):
|
||||||
|
requester = yield self.auth.get_user_by_req(request)
|
||||||
|
|
||||||
try:
|
try:
|
||||||
body = servlet.parse_json_object_from_request(request)
|
body = servlet.parse_json_object_from_request(request)
|
||||||
|
|
||||||
|
@ -135,11 +137,12 @@ class DeviceRestServlet(servlet.RestServlet):
|
||||||
if not authed:
|
if not authed:
|
||||||
defer.returnValue((401, result))
|
defer.returnValue((401, result))
|
||||||
|
|
||||||
requester = yield self.auth.get_user_by_req(request)
|
# check that the UI auth matched the access token
|
||||||
yield self.device_handler.delete_device(
|
user_id = result[constants.LoginType.PASSWORD]
|
||||||
requester.user.to_string(),
|
if user_id != requester.user.to_string():
|
||||||
device_id,
|
raise errors.AuthError(403, "Invalid auth")
|
||||||
)
|
|
||||||
|
yield self.device_handler.delete_device(user_id, device_id)
|
||||||
defer.returnValue((200, {}))
|
defer.returnValue((200, {}))
|
||||||
|
|
||||||
@defer.inlineCallbacks
|
@defer.inlineCallbacks
|
||||||
|
|
Loading…
Reference in a new issue