Skip to content

Commit e680d49

Browse files
committed
fix: enforce authorization on login refresh and logout endpoints
1 parent 944501b commit e680d49

1 file changed

Lines changed: 1 addition & 2 deletions

File tree

src/IdentityManager2/Api/Controllers/PageController.cs

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ namespace IdentityManager2.Api.Controllers
1212
{
1313
[SecurityHeaders]
1414
[ResponseCache(NoStore = true, Location = ResponseCacheLocation.None)]
15+
[Authorize(IdentityManagerConstants.IdMgrAuthPolicy)]
1516
public class PageController : Controller
1617
{
1718
private readonly IdentityManagerOptions config;
@@ -56,7 +57,6 @@ public async Task<IActionResult> Login()
5657
}
5758

5859
[HttpGet]
59-
[AllowAnonymous]
6060
[Route("api/login/refresh")]
6161
public async Task<IActionResult> Refresh()
6262
{
@@ -71,7 +71,6 @@ public async Task<IActionResult> Refresh()
7171
}
7272

7373
[HttpGet]
74-
[AllowAnonymous]
7574
[Route("api/logout", Name = IdentityManagerConstants.RouteNames.Logout)]
7675
public async Task<IActionResult> Logout()
7776
{

0 commit comments

Comments
 (0)