summary refs log tree commit diff
diff options
context:
space:
mode:
authorChrisChrome <christophercookman@gmail.com>2023-01-18 12:26:08 -0700
committerChrisChrome <christophercookman@gmail.com>2023-01-18 12:27:15 -0700
commitca8817919ef0888e73f7605ad557cb0f611d1ec3 (patch)
tree1b0fe0277a1fe4f830baff09b99ce4f1fa8549a4
parentMerge pull request #952 from fosscord/dev/endpoints-in-ping (diff)
downloadserver-ca8817919ef0888e73f7605ad557cb0f611d1ec3.tar.xz
Fix a funny security vuln
-rw-r--r--src/api/routes/guilds/#guild_id/index.ts2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/api/routes/guilds/#guild_id/index.ts b/src/api/routes/guilds/#guild_id/index.ts
index 3f3f61cd..0df90f56 100644
--- a/src/api/routes/guilds/#guild_id/index.ts
+++ b/src/api/routes/guilds/#guild_id/index.ts
@@ -55,7 +55,7 @@ router.get("/", route({}), async (req: Request, res: Response) => {
 
 router.patch(
 	"/",
-	route({ body: "GuildUpdateSchema" }),
+	route({ body: "GuildUpdateSchema", permission: "MANAGE_GUILD" }),
 	async (req: Request, res: Response) => {
 		const body = req.body as GuildUpdateSchema;
 		const { guild_id } = req.params;