Only allow totp removal endpoint for users w/ 2fa

This commit is contained in:
syeopite 2021-07-16 14:37:08 -07:00
parent 413de9c0b1
commit c7b3657878
No known key found for this signature in database
GPG key ID: 6FA616E5A5294A82

View file

@ -35,7 +35,7 @@ class Invidious::Routes::Accounts < Invidious::Routes::BaseRoute
sid = env.get? "sid"
referer = get_referer(env, unroll: false)
if !user
if !user || user.is_a? User && !user.totp_secret
return env.redirect referer
end
@ -54,7 +54,7 @@ class Invidious::Routes::Accounts < Invidious::Routes::BaseRoute
sid = env.get? "sid"
referer = get_referer(env, unroll: false)
if !user
if !user || user.is_a? User && !user.totp_secret
return env.redirect referer
end