Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
ARSnova Backend
Manage
Activity
Members
Labels
Code
Merge requests
0
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Operate
Environments
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Help
Help
Support
GitLab documentation
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Privacy
Imprint
Contact
Snippets
Groups
Projects
Show more breadcrumbs
Paul-Christian Volkmer
ARSnova Backend
Commits
6c19b85e
Commit
6c19b85e
authored
10 years ago
by
Paul-Christian Volkmer
Browse files
Options
Downloads
Patches
Plain Diff
Security fix: Do not provide session creator name/email to users
The creator name is only visible to the creating user itself.
parent
282e9b55
Branches
Branches containing commit
Tags
Tags containing commit
No related merge requests found
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
src/main/java/de/thm/arsnova/controller/SessionController.java
+9
-1
9 additions, 1 deletion
...ain/java/de/thm/arsnova/controller/SessionController.java
with
9 additions
and
1 deletion
src/main/java/de/thm/arsnova/controller/SessionController.java
+
9
−
1
View file @
6c19b85e
...
@@ -42,6 +42,7 @@ import de.thm.arsnova.entities.LoggedIn;
...
@@ -42,6 +42,7 @@ import de.thm.arsnova.entities.LoggedIn;
import
de.thm.arsnova.entities.Session
;
import
de.thm.arsnova.entities.Session
;
import
de.thm.arsnova.exceptions.UnauthorizedException
;
import
de.thm.arsnova.exceptions.UnauthorizedException
;
import
de.thm.arsnova.services.ISessionService
;
import
de.thm.arsnova.services.ISessionService
;
import
de.thm.arsnova.services.IUserService
;
import
de.thm.arsnova.services.SessionService.SessionNameComperator
;
import
de.thm.arsnova.services.SessionService.SessionNameComperator
;
import
de.thm.arsnova.services.SessionService.SessionShortNameComperator
;
import
de.thm.arsnova.services.SessionService.SessionShortNameComperator
;
import
de.thm.arsnova.web.DeprecatedApi
;
import
de.thm.arsnova.web.DeprecatedApi
;
...
@@ -55,9 +56,16 @@ public class SessionController extends AbstractController {
...
@@ -55,9 +56,16 @@ public class SessionController extends AbstractController {
@Autowired
@Autowired
private
ISessionService
sessionService
;
private
ISessionService
sessionService
;
@Autowired
private
IUserService
userService
;
@RequestMapping
(
value
=
"/{sessionkey}"
,
method
=
RequestMethod
.
GET
)
@RequestMapping
(
value
=
"/{sessionkey}"
,
method
=
RequestMethod
.
GET
)
public
final
Session
joinSession
(
@PathVariable
final
String
sessionkey
)
{
public
final
Session
joinSession
(
@PathVariable
final
String
sessionkey
)
{
return
sessionService
.
joinSession
(
sessionkey
);
final
Session
session
=
sessionService
.
joinSession
(
sessionkey
);
if
(
session
.
getCreator
().
equals
(
userService
.
getCurrentUser
().
getUsername
()))
{
session
.
setCreator
(
"NOT VISIBLE TO YOU"
);
}
return
session
;
}
}
@RequestMapping
(
value
=
"/{sessionkey}"
,
method
=
RequestMethod
.
DELETE
)
@RequestMapping
(
value
=
"/{sessionkey}"
,
method
=
RequestMethod
.
DELETE
)
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment