Multiget REPORT requests would happily return tasks from projects different from the one in the href, even though GetTasksByUIDs now filters by access. Drop any returned task whose real project_id does not match the project ID parsed from the href path segment. Hardening for GHSA-48ch-p4gq-x46x. |
||
|---|---|---|
| .. | ||
| auth.go | ||
| handler.go | ||
| listStorageProvider.go | ||
| listStorageProvider_test.go | ||
| main_test.go | ||