Security fix - prevents non-admins to delete alerts via REST

This commit is contained in:
Simone Mainardi 2021-07-02 18:48:54 +02:00
parent a767ad1e26
commit 8f52f33e13
8 changed files with 41 additions and 0 deletions

View file

@ -22,6 +22,11 @@ local system_alert_store = require "system_alert_store".new()
local rc = rest_utils.consts.success.ok
local res = {}
if not isAdministrator() then
rest_utils.answer(rest_utils.consts.err.not_granted)
return
end
interface.select(getSystemInterfaceId())
-- Add filters