From 2e429c0c25c0f82abb6a6b348195cd541052397e Mon Sep 17 00:00:00 2001
From: Clworld <clworld@ggtea.org>
Date: Sun, 28 May 2017 06:27:54 +0900
Subject: [PATCH] Reject revoked access_token on Streaming API. (#3367)

---
 streaming/index.js | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/streaming/index.js b/streaming/index.js
index 908e70d20..5145732e2 100644
--- a/streaming/index.js
+++ b/streaming/index.js
@@ -168,7 +168,7 @@ if (cluster.isMaster) {
         return;
       }
 
-      client.query('SELECT oauth_access_tokens.resource_owner_id, users.account_id, users.filtered_languages FROM oauth_access_tokens INNER JOIN users ON oauth_access_tokens.resource_owner_id = users.id WHERE oauth_access_tokens.token = $1 LIMIT 1', [token], (err, result) => {
+      client.query('SELECT oauth_access_tokens.resource_owner_id, users.account_id, users.filtered_languages FROM oauth_access_tokens INNER JOIN users ON oauth_access_tokens.resource_owner_id = users.id WHERE oauth_access_tokens.token = $1 AND oauth_access_tokens.revoked_at IS NULL LIMIT 1', [token], (err, result) => {
         done();
 
         if (err) {
-- 
GitLab