Authorization before request body validation
aswarcewicz opened this issue · comments
Adrian Swarcewicz commented
When we pass body parser to deadbolt action parsing is invoked before authorization. So when we pass invalid request body and invalid authorization data we get validation error response instead authorization error.
Adrian Swarcewicz commented
It looks that commented routes can be workaround.