PawCorp / walltaker

Take control of your friends wallpapers
12 stars 11 forks source link

[Bug] !Important! private links and expired links are return by api #42

Closed Lycraon closed 2 years ago

Lycraon commented 2 years ago

When requesting https://walltaker.joi.how/api/users/[username].json the links array includes private and expired links.

So if i fetch the json for an user i can see all their links and so get all infos of the links. I would prefer to send an api_key in the same way i send them for reactions, so it only shows links based on the rights of the api user no api would be public info

pupgray commented 2 years ago

Fixed!