Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: disallow API remote-user auth if disabled #6739

Merged
merged 4 commits into from
May 15, 2024

Conversation

shamoon
Copy link
Member

@shamoon shamoon commented May 15, 2024

Proposed change

Closes GHSA-72w4-hxqq-c256

Type of change

  • Bug fix: non-breaking change which fixes an issue.
  • New feature / Enhancement: non-breaking change which adds functionality. Please read the important note above.
  • Breaking change: fix or feature that would cause existing functionality to not work as expected.
  • Documentation only.
  • Other. Please explain: Security

Checklist:

  • I have read & agree with the contributing guidelines.
  • If applicable, I have included testing coverage for new code in this PR, for backend and / or front-end changes.
  • If applicable, I have tested my code for new features & regressions on both mobile & desktop devices, using the latest version of major browsers.
  • If applicable, I have checked that all tests pass, see documentation.
  • I have run all pre-commit hooks, see documentation.
  • I have made corresponding changes to the documentation as needed.
  • I have checked my modifications for any breaking changes.

@shamoon shamoon requested a review from a team as a code owner May 15, 2024 19:54
@paperless-ngx-secretary paperless-ngx-secretary bot added backend non-trivial Requires approval by several team members labels May 15, 2024
@shamoon shamoon added this to the Next Release milestone May 15, 2024
@github-actions github-actions bot added the bug Bug report or a Bug-fix label May 15, 2024
@shamoon shamoon enabled auto-merge (squash) May 15, 2024 19:55
@shamoon shamoon merged commit ed05b40 into dev May 15, 2024
25 checks passed
@shamoon shamoon deleted the fix-GHSA-72w4-hxqq-c256 branch May 15, 2024 20:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backend bug Bug report or a Bug-fix non-trivial Requires approval by several team members
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

None yet

2 participants