grafana/SOURCES/008-CVE-2021-27358.patch

18 lines
444 B
Diff

diff --git a/pkg/middleware/auth.go b/pkg/middleware/auth.go
index c44d7dd9a7..4989ea0e1c 100644
--- a/pkg/middleware/auth.go
+++ b/pkg/middleware/auth.go
@@ -141,9 +141,9 @@ func SnapshotPublicModeOrSignedIn() macaron.Handler {
return
}
- _, err := c.Invoke(ReqSignedIn)
- if err != nil {
- c.JsonApiErr(500, "Failed to invoke required signed in middleware", err)
+ if !c.IsSignedIn {
+ notAuthorized(c)
+ return
}
}
}