diff --git a/server/channels/app/plugin_requests.go b/server/channels/app/plugin_requests.go index 2bb1750f20..2a61ca8738 100644 --- a/server/channels/app/plugin_requests.go +++ b/server/channels/app/plugin_requests.go @@ -208,6 +208,8 @@ func (ch *Channels) servePluginRequest(w http.ResponseWriter, r *http.Request, h if (session != nil && session.Id != "") && err == nil && csrfCheckPassed { r.Header.Set("Mattermost-User-Id", session.UserId) context.SessionId = session.Id + + r.Header.Del(model.HeaderAuth) } } @@ -218,7 +220,6 @@ func (ch *Channels) servePluginRequest(w http.ResponseWriter, r *http.Request, h r.AddCookie(c) } } - r.Header.Del(model.HeaderAuth) r.Header.Del("Referer") params := mux.Vars(r)