Monorepo for Tangled forked from tangled.org/core

appview/oauth: use ResumeSession when fetching currently logged in user master

the final addition to my collection of oauth fixes: the session cookie is not a sufficient indication of a logged-in-ness of a user, we additionally validate this cookie against the session on redis using ResumeSession and kick users out if their session is invalid. previously, a user may have appeared to be logged in (via the profile picture on the top right), but creating an auth'd request would have login-prompted them. Signed-off-by: oppiliappan <me@oppi.li>


Author oppiliappan Committer Tangled Date Commit 7270d3ae Parent ee08cd02 Change ID orvkryxk
+4 -5
1 changed file