better errors on missing token or not matching scope
This commit is contained in:
parent
eed53952a3
commit
8eb7aa11ce
|
@ -31,7 +31,14 @@ class Travis::Api::App
|
||||||
name = settings.default_scope if name == :default
|
name = settings.default_scope if name == :default
|
||||||
headers['X-OAuth-Scopes'] = scopes.map(&:to_s).join(',')
|
headers['X-OAuth-Scopes'] = scopes.map(&:to_s).join(',')
|
||||||
headers['X-Accepted-OAuth-Scopes'] = name.to_s
|
headers['X-Accepted-OAuth-Scopes'] = name.to_s
|
||||||
scopes.include? name
|
|
||||||
|
if scopes.include? name
|
||||||
|
true
|
||||||
|
elsif logged_in?
|
||||||
|
halt 403, "insufficient access"
|
||||||
|
else
|
||||||
|
halt 401, "no access token supplied"
|
||||||
|
end
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue
Block a user