From 9640bd73f05d4bab62bceac98961a6808510fb3f Mon Sep 17 00:00:00 2001 From: Marcus Pasell <3690498+rickyrombo@users.noreply.github.com> Date: Mon, 8 Jun 2026 14:13:51 -0700 Subject: [PATCH] Make redeeming coins use oauth write scope --- api/server.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/api/server.go b/api/server.go index 03f794e3..111186ec 100644 --- a/api/server.go +++ b/api/server.go @@ -504,7 +504,7 @@ func NewApiServer(config config.Config) *ApiServer { g.Get("/tracks/unclaimed_id", app.v1TracksUnclaimedId) g.Get("/tracks/latest", app.v1TracksLatest) - g.Get("/tracks/trending", app.v1TracksTrending) + g.Get("/tracks/trending", app.v1TracksTrending) g.Get("/tracks/trending/ids", app.v1TracksTrendingIds) g.Get("/tracks/trending/winners", app.v1TracksTrendingWinners) g.Get("/tracks/trending/underground", app.v1TracksTrendingUnderground) @@ -688,8 +688,8 @@ func NewApiServer(config config.Config) *ApiServer { g.Get("/coins/:mint/members/count", app.v1CoinMembersCount) g.Get("/coins/:mint/redeem", app.v1CoinsRedeem) g.Get("/coins/:mint/redeem/:code", app.v1CoinsRedeemCode) - g.Post("/coins/:mint/redeem", app.requireAuthMiddleware, app.v1CoinsPostRedeem) - g.Post("/coins/:mint/redeem/:code", app.requireAuthMiddleware, app.v1CoinsPostRedeem) + g.Post("/coins/:mint/redeem", app.requireAuthMiddleware, app.requireWriteScope, app.v1CoinsPostRedeem) + g.Post("/coins/:mint/redeem/:code", app.requireAuthMiddleware, app.requireWriteScope, app.v1CoinsPostRedeem) g.Post("/coins", app.v1CreateCoin) g.Post("/coins/:mint", app.v1UpdateCoin)