Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix the unathenticated vulnerability for ajax/rest endpoints #685

Merged
merged 3 commits into from
Jun 7, 2024

Conversation

ingeniumed
Copy link
Contributor

Description

This PR has been made to a capability check to the preview ajax/rest endpoints, and the get author/hashtag rest endpoints so as to prevent unauthenticated calls from being made. This leverages the existing method already being used for various other endpoints.

@ingeniumed ingeniumed requested review from mjangda and rebeccahum June 6, 2024 01:36
@ingeniumed ingeniumed merged commit 3c7a27c into master Jun 7, 2024
6 of 58 checks passed
@ingeniumed ingeniumed deleted the fix/unauthenticated-ajax-vulnerability branch June 7, 2024 00:19
@GaryJones GaryJones added this to the 1.9.7 milestone Jun 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants