mastodon/app/controllers/api/v1
Eugen Rochko 48fee1a800
Fix poll API not requiring authentication on non-public polls (#10960)
* Fix poll API not requiring authentication on non-public polls

That API does not reveal the content of the status, i.e. the question
itself, nor who the author is, nor which status it belongs to, but it
does reveal the poll options and how many answers they got

Fix #10959

* Add test
2019-06-04 20:10:26 +02:00
..
accounts Improve blocked view of profiles (#10491) 2019-04-07 04:59:13 +02:00
apps
instances Explicitly disable storage of REST API results (#10655) 2019-05-03 20:39:19 +02:00
lists
polls
push Fix web push notifications for polls (#10864) 2019-05-28 00:26:08 +02:00
statuses Improve blocked view of profiles (#10491) 2019-04-07 04:59:13 +02:00
timelines
accounts_controller.rb Improve blocked view of profiles (#10491) 2019-04-07 04:59:13 +02:00
apps_controller.rb
blocks_controller.rb
conversations_controller.rb
custom_emojis_controller.rb Explicitly disable storage of REST API results (#10655) 2019-05-03 20:39:19 +02:00
domain_blocks_controller.rb
endorsements_controller.rb
favourites_controller.rb
filters_controller.rb
follow_requests_controller.rb
follows_controller.rb
instances_controller.rb Explicitly disable storage of REST API results (#10655) 2019-05-03 20:39:19 +02:00
lists_controller.rb
media_controller.rb
mutes_controller.rb
notifications_controller.rb Add account_id param to GET /api/v1/notifications (#10796) 2019-05-21 13:28:49 +02:00
polls_controller.rb Fix poll API not requiring authentication on non-public polls (#10960) 2019-06-04 20:10:26 +02:00
preferences_controller.rb
reports_controller.rb
scheduled_statuses_controller.rb
search_controller.rb
statuses_controller.rb Add toot source to delete result to ease Delete & Redraft (#10669) 2019-05-11 06:46:43 +02:00
streaming_controller.rb
suggestions_controller.rb