From 2e429c0c25c0f82abb6a6b348195cd541052397e Mon Sep 17 00:00:00 2001 From: Clworld Date: Sun, 28 May 2017 06:27:54 +0900 Subject: [PATCH] Reject revoked access_token on Streaming API. (#3367) --- streaming/index.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/streaming/index.js b/streaming/index.js index 908e70d2069..5145732e25d 100644 --- a/streaming/index.js +++ b/streaming/index.js @@ -168,7 +168,7 @@ if (cluster.isMaster) { return; } - client.query('SELECT oauth_access_tokens.resource_owner_id, users.account_id, users.filtered_languages FROM oauth_access_tokens INNER JOIN users ON oauth_access_tokens.resource_owner_id = users.id WHERE oauth_access_tokens.token = $1 LIMIT 1', [token], (err, result) => { + client.query('SELECT oauth_access_tokens.resource_owner_id, users.account_id, users.filtered_languages FROM oauth_access_tokens INNER JOIN users ON oauth_access_tokens.resource_owner_id = users.id WHERE oauth_access_tokens.token = $1 AND oauth_access_tokens.revoked_at IS NULL LIMIT 1', [token], (err, result) => { done(); if (err) {