summary refs log tree commit diff
diff options
context:
space:
mode:
authorChrisChrome <christophercookman@gmail.com>2023-01-18 12:26:08 -0700
committerChrisChrome <christophercookman@gmail.com>2023-01-18 12:27:15 -0700
commit70475d8397fa9ca8b7e62f7e2fc0b4cba6e41dba (patch)
tree1d19f5a5d4a4626b58c136b44230af42f8e30665
parentMerge pull request #952 from fosscord/dev/endpoints-in-ping (diff)
downloadserver-70475d8397fa9ca8b7e62f7e2fc0b4cba6e41dba.tar.xz
Fix a funny security vuln
-rw-r--r--src/api/routes/guilds/#guild_id/index.ts2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/api/routes/guilds/#guild_id/index.ts b/src/api/routes/guilds/#guild_id/index.ts
index 3f3f61cd..0df90f56 100644
--- a/src/api/routes/guilds/#guild_id/index.ts
+++ b/src/api/routes/guilds/#guild_id/index.ts
@@ -55,7 +55,7 @@ router.get("/", route({}), async (req: Request, res: Response) => {
 
 router.patch(
 	"/",
-	route({ body: "GuildUpdateSchema" }),
+	route({ body: "GuildUpdateSchema", permission: "MANAGE_GUILD" }),
 	async (req: Request, res: Response) => {
 		const body = req.body as GuildUpdateSchema;
 		const { guild_id } = req.params;