Skip to content

Commit c6b1cd4

Browse files
committed
AYS-379 | Actuator Endpoints Have Been Allowed to Use without Rate Limit
1 parent daaf7d4 commit c6b1cd4

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/main/java/org/ays/auth/filter/AysBearerTokenAuthenticationFilter.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@ protected void doFilterInternal(@NotNull HttpServletRequest httpServletRequest,
102102
final String tokenId = tokenService.getPayload(jwt).getId();
103103
invalidTokenService.checkForInvalidityOfToken(tokenId);
104104

105-
if (this.isNotAllowedPath(httpServletRequest) || isAuthorizedRateLimitEnabled) {
105+
if (isAuthorizedRateLimitEnabled) {
106106
boolean isRateLimitExceeded = this.isRateLimitExceeded(ipAddress, authorizedBuckets, httpServletResponse);
107107
if (isRateLimitExceeded) {
108108
return;

0 commit comments

Comments
 (0)