Skip to content

Commit

Permalink
#408 Fix a typo on user roles patch API, producing a security issue
Browse files Browse the repository at this point in the history
  • Loading branch information
nadouani committed May 22, 2019
1 parent 55e745f commit 9483b9b
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion thehive-backend/app/controllers/UserCtrl.scala
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ class UserCtrl @Inject() (
else if (request.body.contains("key")) {
Future.failed(AuthorizationError("You must use dedicated API (renewKey, removeKey) to update key"))
}
else if (request.body.contains("role") && !request.authContext.roles.contains(Roles.admin)) {
else if (request.body.contains("roles") && !request.authContext.roles.contains(Roles.admin)) {
Future.failed(AuthorizationError("You are not permitted to change user role"))
}
else if (request.body.contains("status") && !request.authContext.roles.contains(Roles.admin)) {
Expand Down

0 comments on commit 9483b9b

Please sign in to comment.