Alexey Bezhan
36f41c23e1
Always use both folder and service ID when getting template folder
...
Currently there aren't any permission checks based on folder IDs in
the admin app or the API, so it's possible for a user to modify the
folder ID to perform operations on folders outside their service.
Our usual way to avoid this is to always use service_id filter when
fetching objects from the database.
2018-11-07 13:51:37 +00:00
..
2018-03-27 17:37:09 +01:00
2018-08-13 14:09:51 +01:00
2018-10-03 13:07:46 +01:00
2018-10-25 11:12:46 +01:00
2018-05-04 10:56:51 +01:00
2018-07-03 11:11:49 +01:00
2018-11-07 13:51:37 +00:00
2018-08-30 16:36:35 +01:00
2018-09-04 14:40:24 +01:00
2018-04-04 17:10:41 +01:00
2018-06-29 10:26:14 +01:00
2018-04-30 11:47:27 +01:00
2018-10-17 16:09:30 +01:00
2018-10-31 16:48:43 +00:00
2018-06-29 16:14:48 +01:00
2018-10-31 14:28:16 +00:00
2018-11-06 16:22:00 +00:00
2018-10-26 18:02:41 +01:00
2018-10-23 15:52:44 +01:00
2018-11-07 13:51:37 +00:00
2018-07-10 15:04:35 +01:00
2018-09-19 16:32:58 +01:00
2018-10-16 15:08:15 +01:00
2018-10-31 14:28:16 +00:00
2018-09-28 13:52:17 +01:00
2018-10-17 15:29:39 +01:00
2018-04-30 15:25:17 +01:00
2018-04-30 15:25:17 +01:00
2018-11-01 10:44:48 +00:00
2018-10-26 17:54:53 +01:00
2018-07-13 15:47:21 +01:00