Skip to content

Commit 7d4a72c

Browse files
author
Alberto Miedes Garcés
committed
Require an API key for all SQL queries
This was spotted by a client pentest and was required to be fixed
1 parent 2b29d9b commit 7d4a72c

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

lib/api/middlewares/authorization.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ module.exports = function authorization (metadataBackend, forceToBeMaster = fals
88
const { user } = res.locals;
99
const credentials = getCredentialsFromRequest(req);
1010

11-
if (!userMatches(credentials, user)) {
11+
if (!userMatches(credentials, user) || !credentials.apiKeyToken) {
1212
req.profiler.done('authorization');
1313

1414
return next(new Error('permission denied'));

0 commit comments

Comments
 (0)