From e445039cb814ceb625d092cc9f15f1bde07f4b3c Mon Sep 17 00:00:00 2001 From: Adam Shiervani Date: Thu, 2 Jan 2025 21:44:26 +0100 Subject: [PATCH] Don't allow empty tokens (#13) --- web.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web.go b/web.go index 87cbd18..64f8de7 100644 --- a/web.go +++ b/web.go @@ -192,7 +192,7 @@ func protectedMiddleware() gin.HandlerFunc { } authToken, err := c.Cookie("authToken") - if err != nil || authToken != config.LocalAuthToken { + if err != nil || authToken != config.LocalAuthToken || authToken == "" { c.JSON(http.StatusUnauthorized, gin.H{"error": "Unauthorized"}) c.Abort() return