(20250122) User-info fetching mistake.
This commit is contained in:
@@ -233,15 +233,16 @@ async def send_one_mail(
|
||||
# ┗┛┗┻┛┛┗┗ ┛ ┛┛┗┗┣┛ ┗┛┛┗┗ ┗┛┗
|
||||
# ┛
|
||||
|
||||
# We test ownership only in API calls made from outside:
|
||||
if inbound_headers["Remote-IP"] not in current_app.whitelisted_ips:
|
||||
|
||||
# Get the token based on the key:
|
||||
auth_token = await current_app.mail_controller.get_token_from_key(
|
||||
mongo_data_conn = current_app.data_mongo,
|
||||
token_key = inbound_data.tokenKey
|
||||
)
|
||||
|
||||
# Get the user's info:
|
||||
if inbound_headers["Remote-IP"] not in current_app.whitelisted_ips:
|
||||
user_info = CoreUserInfoModel(**kwargs["session_info"])
|
||||
else: user_info = auth_token.user
|
||||
|
||||
# We check if the token that was used to fetch the mail is owned by this user:
|
||||
if not await token_check.is_authorized(
|
||||
|
||||
Reference in New Issue
Block a user