Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add nonce checks for additional security #44

Merged
merged 3 commits into from
Oct 27, 2023
Merged

Conversation

hsein-bitar
Copy link
Contributor

@hsein-bitar hsein-bitar commented Oct 25, 2023

Asana

https://app.asana.com/0/1202852195727075/1205782738893610/f

Context

Draw Attention Security Updates

@hsein-bitar hsein-bitar changed the title Security updates Draw Attention Security Updates Oct 25, 2023
@hsein-bitar
Copy link
Contributor Author

@tylerdigital hello, this should be ready. This PR introduces some security updates to check for user permissions and verify POST nonce values.
I tested:

@hsein-bitar hsein-bitar marked this pull request as ready for review October 25, 2023 11:58
@tylerdigital
Copy link
Collaborator

@cynhu92 could you please do some testing to make sure you can do everything in Draw Attention as expected (creating DA images, removing them, importing them, exporting them, etc). Please test as an administrator, but also as an editor user role to make sure we haven't accidentally broken anything with these security changes

Copy link
Collaborator

@tylerdigital tylerdigital left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@hsein-bitar thanks for the quick turnaround

@hsein-bitar hsein-bitar merged commit de839d8 into master Oct 27, 2023
7 checks passed
@tylerdigital tylerdigital changed the title Draw Attention Security Updates Add Nonce security checks Oct 29, 2023
@tylerdigital tylerdigital changed the title Add Nonce security checks Add nonce checks for additional security Oct 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants