18676: move length check for AnonymousUserToken to lib/config, bring it
[arvados.git] / services / api / app / models / api_client_authorization.rb
index f4bf4f0698ba79f7c712c6fccb3399efd35d18c3..a6beaa07ab38b6a177e9a466f7cd50f737b0edaa 100644 (file)
@@ -124,7 +124,8 @@ class ApiClientAuthorization < ArvadosModel
       secret = token
     end
 
-    if secret.length >= 50 and secret == Rails.configuration.Users.AnonymousUserToken
+    # The anonymous token content and minimum length is verified in lib/config
+    if secret.length >= 0 && secret == Rails.configuration.Users.AnonymousUserToken
       return ApiClientAuthorization.new(user: User.find_by_uuid(anonymous_user_uuid),
                                         uuid: Rails.configuration.ClusterID+"-gj3su-anonymouspublic",
                                         api_token: token,