diff --git a/src/api/routes/webhooks/#webhook_id/#token/github.ts b/src/api/routes/webhooks/#webhook_id/#webhook_token/github.ts
index 140d3618d..140d3618d 100644
--- a/src/api/routes/webhooks/#webhook_id/#token/github.ts
+++ b/src/api/routes/webhooks/#webhook_id/#webhook_token/github.ts
diff --git a/src/api/routes/webhooks/#webhook_id/#token/index.ts b/src/api/routes/webhooks/#webhook_id/#webhook_token/index.ts
index a832c8a21..886236ea5 100644
--- a/src/api/routes/webhooks/#webhook_id/#token/index.ts
+++ b/src/api/routes/webhooks/#webhook_id/#webhook_token/index.ts
@@ -24,7 +24,6 @@ import { Webhook, Message } from "@spacebar/database";
import { Config, DiscordApiErrors, emitEvent, handleFile, ValidateName, WebhooksUpdateEvent } from "@spacebar/util";
import { executeWebhook } from "@spacebar/api/util/handlers/Webhook";
import { WebhookUpdateSchema } from "@spacebar/schemas";
-import { FindOptionsWhere } from "typeorm";
const router = Router({ mergeParams: true });
@@ -40,7 +39,7 @@ router.get(
},
}),
async (req: Request, res: Response) => {
- const { webhook_id, token } = req.params as { [key: string]: string };
+ const { webhook_id, webhook_token } = req.params as { [key: string]: string };
const webhook = await Webhook.findOne({
where: {
id: webhook_id,
@@ -52,7 +51,7 @@ router.get(
throw DiscordApiErrors.UNKNOWN_WEBHOOK;
}
- if (webhook.token !== token) {
+ if (webhook.token !== webhook_token) {
throw DiscordApiErrors.INVALID_WEBHOOK_TOKEN_PROVIDED;
}
@@ -123,7 +122,7 @@ router.delete(
},
}),
async (req: Request, res: Response) => {
- const { webhook_id, token } = req.params as { [key: string]: string };
+ const { webhook_id, webhook_token } = req.params as { [key: string]: string };
const webhook = await Webhook.findOne({
where: {
@@ -132,13 +131,9 @@ router.delete(
relations: { channel: true, guild: true, application: true },
});
- if (!webhook) {
- throw DiscordApiErrors.UNKNOWN_WEBHOOK;
- }
+ if (!webhook) throw DiscordApiErrors.UNKNOWN_WEBHOOK;
+ if (webhook.token !== webhook_token) throw DiscordApiErrors.INVALID_WEBHOOK_TOKEN_PROVIDED;
- if (webhook.token !== token) {
- throw DiscordApiErrors.INVALID_WEBHOOK_TOKEN_PROVIDED;
- }
const channel_id = webhook.channel_id;
await Message.delete({ channel_id, webhook_id });
await Webhook.delete({ id: webhook_id });
@@ -172,14 +167,17 @@ router.patch(
},
}),
async (req: Request, res: Response) => {
- // noinspection JSUnusedLocalSymbols - TODO: shouldnt token be checked?
- const { webhook_id, token } = req.params as { [key: string]: string };
+ const { webhook_id, webhook_token } = req.params as { [key: string]: string };
const body = req.body as WebhookUpdateSchema;
- const webhook = await Webhook.findOneOrFail({
+ const webhook = await Webhook.findOne({
where: { id: webhook_id },
relations: { user: true, channel: true, source_channel: true, guild: true, source_guild: true, application: true },
});
+
+ if (!webhook) throw DiscordApiErrors.UNKNOWN_WEBHOOK;
+ if (webhook.token != webhook_token) throw DiscordApiErrors.INVALID_WEBHOOK_TOKEN_PROVIDED;
+
const channel_id = webhook.channel_id;
if (!body.name && !body.avatar) {
throw new HTTPError("Empty webhook updates are not allowed", 50006);
diff --git a/src/api/util/handlers/Webhook.ts b/src/api/util/handlers/Webhook.ts
index 1f4f60a73..3e1114ab2 100644
--- a/src/api/util/handlers/Webhook.ts
+++ b/src/api/util/handlers/Webhook.ts
@@ -28,7 +28,7 @@ export const executeWebhook = async (req: Request, res: Response) => {
const body = req.body as WebhookExecuteSchema;
const messageId = Snowflake.generate();
- const { webhook_id, token } = req.params as { [key: string]: string };
+ const { webhook_id, webhook_token } = req.params as { [key: string]: string };
const webhook = await Webhook.findOne({
where: {
@@ -37,13 +37,8 @@ export const executeWebhook = async (req: Request, res: Response) => {
relations: { channel: true, guild: true, application: true },
});
- if (!webhook) {
- throw DiscordApiErrors.UNKNOWN_WEBHOOK;
- }
-
- if (webhook.token !== token) {
- throw DiscordApiErrors.INVALID_WEBHOOK_TOKEN_PROVIDED;
- }
+ if (!webhook) throw DiscordApiErrors.UNKNOWN_WEBHOOK;
+ if (webhook.token !== webhook_token) throw DiscordApiErrors.INVALID_WEBHOOK_TOKEN_PROVIDED;
if (body.username) {
ValidateName(body.username);
|