Skip to content

Commit 0949fb5

Browse files
committed
Catch bad authentication in trusted_recording_signed_request
Return a failed authentication error in trusted_recording_signed_request if the request doesn't include a signed request.
1 parent e27b342 commit 0949fb5

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

lib/cube/authentication.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -98,9 +98,9 @@ authentication.trusted_recording_signed_request = function(db, options) {
9898
return auth_ok({ anonymous: true});
9999
}
100100
var authHeader = request.headers.authorization;
101-
var signedReq = signedRequest.parseSignedRequest(authHeader.substr(15));
102-
var payload = signedReq.payload;
103101
try {
102+
var signedReq = signedRequest.parseSignedRequest(authHeader.substr(15));
103+
var payload = signedReq.payload;
104104
payload = signedRequest.deserializePayload(payload);
105105
auth_ok({
106106
email: payload.context.user.email,

0 commit comments

Comments
 (0)