Skip to content

Commit b2de038

Browse files
committed
fix: Privilege Escalation Vulnerability
1 parent 0d9bc62 commit b2de038

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

backend/apps/datasource/api/datasource.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -162,7 +162,7 @@ async def get_fields(session: SessionDep,
162162

163163

164164
@router.post("/syncFields/{id}", response_model=None, summary=f"{PLACEHOLDER_PREFIX}ds_sync_fields")
165-
@require_permissions(permission=SqlbotPermission(role=['ws_admin'], type='ds', keyExpression="id"))
165+
@require_permissions(permission=SqlbotPermission(role=['ws_admin']))
166166
async def sync_fields(session: SessionDep, trans: Trans,
167167
id: int = Path(..., description=f"{PLACEHOLDER_PREFIX}ds_table_id")):
168168
return sync_single_fields(session, trans, id)

0 commit comments

Comments
 (0)