Multiget REPORT requests would happily return tasks from projects different from the one in the href, even though GetTasksByUIDs now filters by access. Drop any returned task whose real project_id does not match the project ID parsed from the href path segment. Hardening for GHSA-48ch-p4gq-x46x. |
||
|---|---|---|
| .. | ||
| api/v1 | ||
| caldav | ||
| api_tokens.go | ||
| error_handler.go | ||
| healthcheck.go | ||
| metrics.go | ||
| rate_limit.go | ||
| routes.go | ||
| sentry_middleware.go | ||
| static.go | ||
| validation.go | ||