dataware-tools / api-file-provider

0 stars 0 forks source link

Fix vulnerability on downloading and deleting file #29

Closed yusukefs closed 3 years ago

yusukefs commented 3 years ago

What?

ファイルのパスではなくUUIDを受け取り、meta-store からパスを取得するようにした

Why?

ファイルのダウンロード・削除時の権限チェック回避バグを修正するため

See also [Optional]

https://github.com/dataware-tools/dataware-tools/issues/72

Screenshot or video [Optional]

hdl-service commented 3 years ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: d-hayashi, yusukefs

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/dataware-tools/api-file-provider/blob/master/OWNERS)~~ [d-hayashi,yusukefs] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment