Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
ARSnova Backend
Manage
Activity
Members
Labels
Code
Merge requests
0
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Operate
Environments
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Help
Help
Support
GitLab documentation
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Privacy
Imprint
Contact
Snippets
Groups
Projects
Show more breadcrumbs
Paul-Christian Volkmer
ARSnova Backend
Commits
3db4cf50
Commit
3db4cf50
authored
8 years ago
by
Daniel Gerhardt
Browse files
Options
Downloads
Patches
Plain Diff
Fix security vulnerability in account management API
parent
9c210c10
No related merge requests found
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
src/main/java/de/thm/arsnova/controller/UserController.java
+1
-1
1 addition, 1 deletion
src/main/java/de/thm/arsnova/controller/UserController.java
src/main/java/de/thm/arsnova/services/UserService.java
+1
-1
1 addition, 1 deletion
src/main/java/de/thm/arsnova/services/UserService.java
with
2 additions
and
2 deletions
src/main/java/de/thm/arsnova/controller/UserController.java
+
1
−
1
View file @
3db4cf50
...
...
@@ -95,7 +95,7 @@ public class UserController extends AbstractController {
response
.
setStatus
(
HttpServletResponse
.
SC_BAD_REQUEST
);
}
@RequestMapping
(
value
=
{
"/{username}"
},
method
=
RequestMethod
.
DELETE
)
@RequestMapping
(
value
=
{
"/{username}
/
"
},
method
=
RequestMethod
.
DELETE
)
public
final
void
activate
(
@PathVariable
final
String
username
,
final
HttpServletRequest
request
,
...
...
This diff is collapsed.
Click to expand it.
src/main/java/de/thm/arsnova/services/UserService.java
+
1
−
1
View file @
3db4cf50
...
...
@@ -408,7 +408,7 @@ public class UserService implements IUserService {
public
DbUser
deleteDbUser
(
String
username
)
{
User
user
=
getCurrentUser
();
if
(!
user
.
getUsername
().
equals
(
username
)
&&
SecurityContextHolder
.
getContext
().
getAuthentication
().
getAuthorities
()
&&
!
SecurityContextHolder
.
getContext
().
getAuthentication
().
getAuthorities
()
.
contains
(
new
SimpleGrantedAuthority
(
"ROLE_ADMIN"
)))
{
throw
new
UnauthorizedException
();
}
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment