Use OTKPreAuthFilter attributes instead of re-validating OTK in NotesController

FixSecurityService
Shipped
March 23, 2026 at 1:56 AM UTC
Author
Kamo
Commit
cdb3b68

The OTKPreAuthFilter already consumes and validates the OTK, storing the session data in request attributes. NotesController was trying to re-validate the already-consumed OTK, causing authentication failures. Now reads from request attributes first, matching MemberController pattern.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing