diff --git a/app/controllers/api/base_controller.rb b/app/controllers/api/base_controller.rb index c46fde65b23..883f60c8edf 100644 --- a/app/controllers/api/base_controller.rb +++ b/app/controllers/api/base_controller.rb @@ -133,7 +133,13 @@ class Api::BaseController < ApplicationController end def disallow_unauthenticated_api_access? - authorized_fetch_mode? + if ENV['DISALLOW_UNAUTHENTICATED_API_ACCESS'] == 'true' + true + elsif ENV['DISALLOW_UNAUTHENTICATED_API_ACCESS'] == 'false' + false + else + authorized_fetch_mode? + end end private