Replaced AJAX by fetch: not everything tested yet, but seems fine
[vchess.git] / server / routes / users.js
index 1196675..2b38c37 100644 (file)
@@ -34,7 +34,7 @@ router.post('/register', access.unlogged, access.ajax, (req,res) => {
 });
 
 // NOTE: this method is safe because the sessionToken must be guessed
-router.get("/whoami", (req,res) => {
+router.get("/whoami", access.ajax, (req,res) => {
   const callback = (user) => {
     res.json({
       name: user.name,