allow delete with token

This commit is contained in:
Q
2024-01-14 10:34:46 +02:00
parent dd30147233
commit 7c02ca1956

View File

@@ -224,12 +224,6 @@ def delete_file(name, token):
secret = request.headers.get("Secret", "") secret = request.headers.get("Secret", "")
if secret != app.config["ACCESS_TOKEN"]: if secret != app.config["ACCESS_TOKEN"]:
return "Error", 401 return "Error", 401
details = file_details(token, name)
if details["allowed_ip"] is not None:
if not is_ip_allowed(
details["allowed_ip"], request.environ.get("HTTP_X_FORWARDED_FOR", request.remote_addr), app
):
return "Not Allowed", 403
try: try:
os.remove(os.path.join(app.config["DATAFOLDER"], token, name)) os.remove(os.path.join(app.config["DATAFOLDER"], token, name))