Erik Johnston 74c46d81fa Only require consent for events with an associated request
There are a number of instances where a server or admin may puppet a
user to join/leave rooms, which we don't want to fail if the user has
not consented to the privacy policy. We fix this by adding a check to
test if the requester has an associated access_token, which is used as a
proxy to answer the question of whether the action is being done on
behalf of a real request from the user.
2019-03-20 16:50:23 +00:00
..
2016-01-07 04:26:29 +00:00
2018-07-09 16:09:20 +10:00
2018-07-09 16:09:20 +10:00
2019-03-08 11:26:33 +00:00
2019-02-25 16:56:41 +00:00
2019-02-18 18:23:37 +00:00
2019-01-24 17:22:09 +00:00
2018-07-09 16:09:20 +10:00