Patched some holes when poking with curl

This commit is contained in:
2021-07-24 20:04:35 +10:00
parent 46ded91c41
commit c63e14ddf3
8 changed files with 49 additions and 26 deletions
+3 -1
View File
@@ -17,6 +17,9 @@ router.post('/token', require('./token'));
//middleware
router.use(tokenAuth);
//logouts allowed when banned, still needs tokens
router.delete('/logout', require('./logout'));
router.use(async (req, res, next) => {
const record = await accounts.findOne({
where: {
@@ -36,7 +39,6 @@ router.use(async (req, res, next) => {
});
//basic account management (needs a token)
router.delete('/logout', require('./logout'));
router.get('/account', require('./account-query'));
router.patch('/account', require('./account-update'));
router.delete('/account', require('./account-delete'));