From 0c3e287fa8acca29cbf041d5e3200a4e4b1e316e Mon Sep 17 00:00:00 2001 From: mike12345567 Date: Sat, 27 Feb 2021 10:15:05 +0000 Subject: [PATCH 1/2] Very minor change due to issue #1204 - wasn't allowing unauthenticated requests through. --- packages/server/src/api/routes/webhook.js | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/packages/server/src/api/routes/webhook.js b/packages/server/src/api/routes/webhook.js index fdcf14e490..cb65ac66cb 100644 --- a/packages/server/src/api/routes/webhook.js +++ b/packages/server/src/api/routes/webhook.js @@ -40,10 +40,7 @@ router authorized(BUILDER), controller.buildSchema ) - .post( - "/api/webhooks/trigger/:instance/:id", - authorized(PermissionTypes.WEBHOOK, PermissionLevels.EXECUTE), - controller.trigger - ) + // this shouldn't have authorisation, right now its always public + .post("/api/webhooks/trigger/:instance/:id", controller.trigger) module.exports = router From 554b5a27c6a521c0b4739db5e5a75b1e6b4aff03 Mon Sep 17 00:00:00 2001 From: mike12345567 Date: Sat, 27 Feb 2021 10:45:01 +0000 Subject: [PATCH 2/2] Linting. --- packages/server/src/api/routes/webhook.js | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/packages/server/src/api/routes/webhook.js b/packages/server/src/api/routes/webhook.js index cb65ac66cb..7a5577c564 100644 --- a/packages/server/src/api/routes/webhook.js +++ b/packages/server/src/api/routes/webhook.js @@ -2,11 +2,7 @@ const Router = require("@koa/router") const controller = require("../controllers/webhook") const authorized = require("../../middleware/authorized") const joiValidator = require("../../middleware/joi-validator") -const { - BUILDER, - PermissionTypes, - PermissionLevels, -} = require("../../utilities/security/permissions") +const { BUILDER } = require("../../utilities/security/permissions") const Joi = require("joi") const router = Router()