Hide door card list behind auth token

This commit is contained in:
2020-02-27 22:44:55 +00:00
parent ecefa479ee
commit f82c7e4a73
2 changed files with 10 additions and 0 deletions

View File

@@ -317,6 +317,10 @@ class PingView(views.APIView):
class DoorViewSet(viewsets.ViewSet, List):
def list(self, request):
auth_token = request.META.get('HTTP_AUTHORIZATION', '')
if auth_token != secrets.DOOR_API_TOKEN:
raise exceptions.PermissionDenied()
cards = models.Card.objects.filter(active_status='card_active')
active_member_cards = {}