From 2b11f8adfac747e7281728cea0b3381a95689990 Mon Sep 17 00:00:00 2001 From: mike12345567 Date: Sat, 27 Feb 2021 10:15:05 +0000 Subject: [PATCH 1/2] Very minor change due to issue #1204 - wasn't allowing unauthenticated requests through. --- packages/server/src/api/routes/webhook.js | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/packages/server/src/api/routes/webhook.js b/packages/server/src/api/routes/webhook.js index fdcf14e490..cb65ac66cb 100644 --- a/packages/server/src/api/routes/webhook.js +++ b/packages/server/src/api/routes/webhook.js @@ -40,10 +40,7 @@ router authorized(BUILDER), controller.buildSchema ) - .post( - "/api/webhooks/trigger/:instance/:id", - authorized(PermissionTypes.WEBHOOK, PermissionLevels.EXECUTE), - controller.trigger - ) + // this shouldn't have authorisation, right now its always public + .post("/api/webhooks/trigger/:instance/:id", controller.trigger) module.exports = router From 2e7410bc717bdbb4aa08e5b3bafbdb919c05a663 Mon Sep 17 00:00:00 2001 From: mike12345567 Date: Sat, 27 Feb 2021 10:45:01 +0000 Subject: [PATCH 2/2] Linting. --- packages/server/src/api/routes/webhook.js | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/packages/server/src/api/routes/webhook.js b/packages/server/src/api/routes/webhook.js index cb65ac66cb..7a5577c564 100644 --- a/packages/server/src/api/routes/webhook.js +++ b/packages/server/src/api/routes/webhook.js @@ -2,11 +2,7 @@ const Router = require("@koa/router") const controller = require("../controllers/webhook") const authorized = require("../../middleware/authorized") const joiValidator = require("../../middleware/joi-validator") -const { - BUILDER, - PermissionTypes, - PermissionLevels, -} = require("../../utilities/security/permissions") +const { BUILDER } = require("../../utilities/security/permissions") const Joi = require("joi") const router = Router()