All data under /public is always readable

This commit is contained in:
2012-09-25 17:34:40 +02:00
parent af28ec44c8
commit 9e81c4828d
2 changed files with 14 additions and 1 deletions

View File

@@ -14,7 +14,7 @@ module RemoteStorage
def authorize_request(user, category, token)
request_method = env["REQUEST_METHOD"]
return true if category == "public" && request_method == "GET"
return true if category.split("/").first == "public" && request_method == "GET"
authorizations = client.bucket("authorizations").get("#{user}:#{token}").data
permission = category_permission(authorizations, category)