Erik Johnston 74c46d81fa Only require consent for events with an associated request
There are a number of instances where a server or admin may puppet a
user to join/leave rooms, which we don't want to fail if the user has
not consented to the privacy policy. We fix this by adding a check to
test if the requester has an associated access_token, which is used as a
proxy to answer the question of whether the action is being done on
behalf of a real request from the user.
2019-03-20 16:50:23 +00:00
..
2019-01-30 10:53:17 +00:00
2019-03-19 11:30:54 +00:00
2019-03-08 15:05:32 +00:00
2019-02-22 15:27:40 +00:00
2019-03-15 17:46:16 +00:00
2019-01-29 23:09:10 +00:00
2019-03-01 10:55:44 +00:00
2019-03-13 20:02:56 +00:00
2019-03-13 17:20:55 +00:00
2019-03-06 16:22:16 +00:00