logins: don't return api_token field in API.

Remove the api_token field from the response to the login action (POST
/sessions). This doesn't make sense in the presence of multiple API
keys, and is also not generally useful; if you need an API key, create
one yourself and write it down.
This commit is contained in:
evazion
2021-02-15 14:22:59 -06:00
parent 206ff2b836
commit 3798a2d29e
3 changed files with 3 additions and 6 deletions

View File

@@ -15,7 +15,7 @@ class SessionsController < ApplicationController
if user
url = posts_path unless url&.start_with?("/")
respond_with(user, location: url, methods: [:api_token])
respond_with(user, location: url)
else
flash.now[:notice] = "Password was incorrect"
raise SessionLoader::AuthenticationFailure