From ca3af6c5b00be851e2ced9112429cfc1baa79529 Mon Sep 17 00:00:00 2001 From: multiple creatures Date: Sun, 10 May 2020 03:02:22 -0500 Subject: Port monsterfork@58c707c474 make data miners' lives harder by also requiring authentication on account api endpoints --- app/controllers/api/v1/accounts/search_controller.rb | 1 + 1 file changed, 1 insertion(+) (limited to 'app/controllers/api/v1/accounts/search_controller.rb') diff --git a/app/controllers/api/v1/accounts/search_controller.rb b/app/controllers/api/v1/accounts/search_controller.rb index 3061fcb7e..aa8745931 100644 --- a/app/controllers/api/v1/accounts/search_controller.rb +++ b/app/controllers/api/v1/accounts/search_controller.rb @@ -12,6 +12,7 @@ class Api::V1::Accounts::SearchController < Api::BaseController private def account_search + return Account.none unless user_signed_in? AccountSearchService.new.call( params[:q], current_account, -- cgit