Fix admin API unconditionally requiring CSRF token (#17975)
Fixes #17898 Since #17204, the admin API has only been available through the web application because of the unconditional requirement to provide a valid CSRF token. This commit changes it back to `null_session`, which should make it work both with session-based authentication (provided a CSRF token) and with a bearer token.
This commit is contained in:
		@@ -1,8 +1,6 @@
 | 
			
		||||
# frozen_string_literal: true
 | 
			
		||||
 | 
			
		||||
class Api::V1::Admin::Trends::LinksController < Api::BaseController
 | 
			
		||||
  protect_from_forgery with: :exception
 | 
			
		||||
 | 
			
		||||
  before_action -> { authorize_if_got_token! :'admin:read' }
 | 
			
		||||
  before_action :require_staff!
 | 
			
		||||
  before_action :set_links
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user