From 237f49d75427e91126b1b68986c1a7e59c60f762 Mon Sep 17 00:00:00 2001 From: Brent Date: Mon, 17 Jun 2019 10:02:45 -0600 Subject: [PATCH] fix(current_user): revert set_user_by_token false return when token not present (#1306) --- app/controllers/devise_token_auth/concerns/set_user_by_token.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/devise_token_auth/concerns/set_user_by_token.rb b/app/controllers/devise_token_auth/concerns/set_user_by_token.rb index 364ff9b6a..027a9261a 100644 --- a/app/controllers/devise_token_auth/concerns/set_user_by_token.rb +++ b/app/controllers/devise_token_auth/concerns/set_user_by_token.rb @@ -62,7 +62,7 @@ def set_user_by_token(mapping = nil) # ensure we clear the client unless @token.present? @token.client = nil - return false + return end # mitigate timing attacks by finding by uid instead of auth token