fix: prevent webapp token used in console

This commit is contained in:
GareArc 2025-05-30 16:10:48 +08:00
parent bb9ec1a587
commit 8c78286e5f
No known key found for this signature in database

View File

@ -37,6 +37,9 @@ def load_user_from_request(request_from_flask_login):
raise Unauthorized("Invalid Authorization token.")
decoded = PassportService().verify(auth_token)
user_id = decoded.get("user_id")
source = decoded.get("token_source")
if source:
raise Unauthorized("Invalid Authorization token.")
if not user_id:
raise Unauthorized("Invalid Authorization token.")