Use webapp secret instead of bot token

This commit is contained in:
Jeremy Zhang
2018-08-10 04:22:24 +00:00
parent cb0f1b249e
commit 6d06b4001f
3 changed files with 6 additions and 4 deletions

View File

@ -553,7 +553,7 @@ def webhook_discordbotsorg_vote():
@api.route("/bot/ban", methods=["POST"])
def bot_ban():
if request.headers.get("Authorization", "") != config.get("bot-token", ""):
if request.headers.get("Authorization", "") != config.get("app-secret", ""):
return jsonify(error="Authorization header does not match."), 403
incoming = request.get_json()
guild_id = incoming.get("guild_id", None)
@ -590,7 +590,7 @@ def bot_ban():
@api.route("/bot/revoke", methods=["POST"])
def bot_revoke():
if request.headers.get("Authorization", "") != config.get("bot-token", ""):
if request.headers.get("Authorization", "") != config.get("app-secret", ""):
return jsonify(error="Authorization header does not match."), 403
incoming = request.get_json()
guild_id = incoming.get("guild_id", None)