security: hide draft posts from public detail endpoint
Add post.draft? check to GET /api/volumen/posts/:slug so guessing a draft slug returns 404 like the list endpoint already does.
This commit is contained in:
@@ -19,7 +19,7 @@ module Volumen
|
||||
|
||||
app.get "/api/volumen/posts/:slug" do
|
||||
post = store.find(params["slug"], lang: params["lang"])
|
||||
halt(404, json("error" => "not_found")) if post.nil?
|
||||
halt(404, json("error" => "not_found")) if post.nil? || post.draft?
|
||||
|
||||
json(post.detail)
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user