Skip to content
This repository has been archived by the owner on Jan 13, 2023. It is now read-only.

Fix vulnerability on downloading and deleting file #29

Merged
merged 3 commits into from
Sep 9, 2021

Conversation

yusukefs
Copy link
Contributor

@yusukefs yusukefs commented Sep 8, 2021

What?

ファイルのパスではなくUUIDを受け取り、meta-store からパスを取得するようにした

Why?

ファイルのダウンロード・削除時の権限チェック回避バグを修正するため

See also [Optional]

dataware-tools/dataware-tools#72

Screenshot or video [Optional]

@hdl-service hdl-service added approved Indicates a PR has been approved by an approver from all required OWNERS files. size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 8, 2021
@yusukefs yusukefs requested review from d-hayashi and removed request for WatanabeToshimitsu September 8, 2021 13:11
Copy link
Contributor

@d-hayashi d-hayashi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@hdl-service hdl-service added the lgtm Indicates that a PR is ready to be merged. label Sep 9, 2021
@hdl-service
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: d-hayashi, yusukefs

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@hdl-service hdl-service merged commit d14ecff into master Sep 9, 2021
@hdl-service hdl-service deleted the fix/vulnerability-on-download-and-delete-file branch September 9, 2021 01:34
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants