Security fix: any user can delete any feed
Regression introduced in commit 51fb949
.
This commit is contained in:
parent
fa49bcaf8b
commit
32439ca2f0
2 changed files with 7 additions and 1 deletions
|
@ -381,7 +381,7 @@ func (s *Storage) RemoveFeed(userID, feedID int64) error {
|
|||
}
|
||||
}
|
||||
|
||||
if _, err := s.db.Exec(`DELETE FROM feeds WHERE id=$1`, feedID); err != nil {
|
||||
if _, err := s.db.Exec(`DELETE FROM feeds WHERE id=$1 AND user_id=$2`, feedID, userID); err != nil {
|
||||
return fmt.Errorf(`store: unable to delete feed #%d: %v`, feedID, err)
|
||||
}
|
||||
|
||||
|
|
|
@ -14,6 +14,12 @@ import (
|
|||
|
||||
func (h *handler) removeFeed(w http.ResponseWriter, r *http.Request) {
|
||||
feedID := request.RouteInt64Param(r, "feedID")
|
||||
|
||||
if !h.store.FeedExists(request.UserID(r), feedID) {
|
||||
html.NotFound(w, r)
|
||||
return
|
||||
}
|
||||
|
||||
if err := h.store.RemoveFeed(request.UserID(r), feedID); err != nil {
|
||||
html.ServerError(w, r, err)
|
||||
return
|
||||
|
|
Loading…
Reference in a new issue