diff --git a/app/controllers/devise_token_auth/concerns/set_user_by_token.rb b/app/controllers/devise_token_auth/concerns/set_user_by_token.rb index 364ff9b6a..027a9261a 100644 --- a/app/controllers/devise_token_auth/concerns/set_user_by_token.rb +++ b/app/controllers/devise_token_auth/concerns/set_user_by_token.rb @@ -62,7 +62,7 @@ def set_user_by_token(mapping = nil) # ensure we clear the client unless @token.present? @token.client = nil - return false + return end # mitigate timing attacks by finding by uid instead of auth token