Dan Brown 349b4629be
Extracted API auth into guard
Also implemented more elegant solution to allowing session auth for API
routes; A new 'StartSessionIfCookieExists' middleware, which wraps the
default 'StartSession' middleware will run for API routes which only
sets up the session if a session cookie is found on the request. Also
decrypts only the session cookie.

Also cleaned some TokenController codeclimate warnings.
2019-12-30 14:51:28 +00:00
..
2019-12-28 14:58:07 +00:00
2019-12-30 14:51:28 +00:00
2019-09-13 23:58:40 +01:00
2019-07-06 13:44:50 +01:00
2019-09-13 23:58:40 +01:00
2019-09-06 23:36:16 +01:00
2019-07-06 13:44:50 +01:00
2019-07-06 13:44:50 +01:00