Allow get release download files and lfs files with oauth2 token format (#26430)

Fix #26165
Fix #25257
This commit is contained in:
Lunny Xiao authored and GitHub committed 2023-10-01 10:41:52 +00:00
1 parent 6b65c41ebf
commit 6e87a44034
8 files changed
+66 -6

No files matched your search

+3 -1
View File
@@ -125,7 +125,9 @@ func (o *OAuth2) userIDFromToken(ctx context.Context, tokenSHA string, store Dat
// If verification is successful returns an existing user object.
// Returns nil if verification fails.
func (o *OAuth2) Verify(req *http.Request, w http.ResponseWriter, store DataStore, sess SessionStore) (*user_model.User, error) {
if !middleware.IsAPIPath(req) && !isAttachmentDownload(req) && !isAuthenticatedTokenRequest(req) {
// These paths are not API paths, but we still want to check for tokens because they maybe in the API returned URLs
if !middleware.IsAPIPath(req) && !isAttachmentDownload(req) && !isAuthenticatedTokenRequest(req) &&
!gitRawReleasePathRe.MatchString(req.URL.Path) {
return nil, nil
}