diff options
author | Richard van der Hoff <github@rvanderhoff.org.uk> | 2016-12-06 15:31:37 +0000 |
---|---|---|
committer | GitHub <noreply@github.com> | 2016-12-06 15:31:37 +0000 |
commit | 1529c196758ec4106f4b3a0f89f5b41bc5205c7b (patch) | |
tree | cc2f0cd5bd53cd5f58b79e67cfab5f5f62c3d94a /synapse/handlers | |
parent | Travis config (#1674) (diff) | |
download | synapse-1529c196758ec4106f4b3a0f89f5b41bc5205c7b.tar.xz |
Prevent user tokens being used as guest tokens (#1675)
Make sure that a user cannot pretend to be a guest by adding 'guest = True' caveats.
Diffstat (limited to 'synapse/handlers')
-rw-r--r-- | synapse/handlers/register.py | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/synapse/handlers/register.py b/synapse/handlers/register.py index 886fec8701..286f0cef0a 100644 --- a/synapse/handlers/register.py +++ b/synapse/handlers/register.py @@ -81,7 +81,7 @@ class RegistrationHandler(BaseHandler): "User ID already taken.", errcode=Codes.USER_IN_USE, ) - user_data = yield self.auth.get_user_from_macaroon(guest_access_token) + user_data = yield self.auth.get_user_by_access_token(guest_access_token) if not user_data["is_guest"] or user_data["user"].localpart != localpart: raise AuthError( 403, |