hack4impact-utk / compassion-ministries

https://compassion-ministries.vercel.app
1 stars 2 forks source link

Security on POST /api/bc-webhook #340

Open andlrutt opened 2 months ago

andlrutt commented 2 months ago

Description

Currently SpringVerify hits a webhook api when the background check is finished. This works, but anyone can currently call this endpoint without authorization. Theoretically someone could approve their own background check. Can we lock this down?

Technical Details

Dependencies