mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-04-26 01:35:54 +03:00
[GH-ISSUE #33] Protect Organization related GET requests #10
Labels
No labels
SSO
Third party
better for forum
bug
bug
documentation
duplicate
enhancement
future Vault
future Vault
future Vault
good first issue
help wanted
low priority
notes
pull-request
question
troubleshooting
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vaultwarden#10
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @mprasil on GitHub (May 29, 2018).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/33
It seems that we don't really check user's access rights when doing
/organization/*API calls. While this is mostly harmless in theory, we should probably protect all of these under some common check.It think implementing some form of request guard would probably be the best way to handle that.
@mprasil commented on GitHub (May 30, 2018):
Submitted an PR #34 to fix this.