From: Eugen Date: Sun, 9 Apr 2017 20:21:52 +0000 (+0200) Subject: Do not store last visited URL from API controllers (#1330) X-Git-Url: https://git.xn--scling-oua.cat.family/?a=commitdiff_plain;h=93db265be7b648fe095d5a92b76c5c7077c72ac2;p=mastodon.git Do not store last visited URL from API controllers (#1330) Sign-in redirects you back to last visited URL, but in case of API requests, this sometimes redirected users to an API URL that, of course, greeted them with an {"error":"The access token is invalid"} --- diff --git a/app/controllers/api_controller.rb b/app/controllers/api_controller.rb index db16f82e5..57604f1dc 100644 --- a/app/controllers/api_controller.rb +++ b/app/controllers/api_controller.rb @@ -7,6 +7,7 @@ class ApiController < ApplicationController protect_from_forgery with: :null_session skip_before_action :verify_authenticity_token + skip_before_action :store_current_location before_action :set_rate_limit_headers