Files
requestarr/server/routes
Gauthier 946bdecec5 Merge commit from fork
This PR fixes a security issue where authenticated users could access and modify data belonging to
other users. The isOwnProfileOrAdmin() middleware was missing from several push subscription API
routes. As a result, any authenticated user on the instance could manipulate the userId parameter in
the URL to view or delete the push subscriptions of other users.
2026-02-28 00:58:50 +08:00
..
2026-02-28 00:58:50 +08:00
2026-02-28 00:36:17 +08:00
2024-12-29 05:20:35 +08:00
2024-06-19 18:40:25 +05:00
2024-06-19 18:40:25 +05:00