user_status redirect: check visibility independent of token

This commit is contained in:
Daniel Friesel 2023-03-02 21:54:17 +01:00
parent 6a734a094b
commit aa56023788
No known key found for this signature in database
GPG key ID: 100D5BFB5166E005

View file

@ -528,12 +528,10 @@ sub user_status {
)
)
{
my $token = $self->param('token');
if ($token) {
my $visibility = $self->compute_effective_visibility(
my $visibility
= $self->compute_effective_visibility(
$user->{default_visibility_str},
$journey->{visibility_str}
);
$journey->{visibility_str} );
if (
$visibility eq 'public'
or ( $visibility eq 'unlisted'
@ -545,16 +543,13 @@ sub user_status {
)
)
{
my $token = $self->param('token') // q{};
$self->redirect_to(
"/p/${name}/j/$journey->{id}?token=${token}-${ts}");
}
else {
$self->render('not_found');
}
}
else {
$self->redirect_to("/p/${name}/j/$journey->{id}");
}
return;
}
$self->render('not_found');