Skip to content

[PM-25820] Return DeleteAttachmentResponseModel from cipher attachment delete endpoints#7013

Open
gbubemismith wants to merge 2 commits intomainfrom
vault/PM-25820-cipher-response-model
Open

[PM-25820] Return DeleteAttachmentResponseModel from cipher attachment delete endpoints#7013
gbubemismith wants to merge 2 commits intomainfrom
vault/PM-25820-cipher-response-model

Conversation

@gbubemismith
Copy link
Contributor

🎟️ Tracking

https://bitwarden.atlassian.net/browse/PM-25820

📔 Objective

Updates the DeleteAttachment and DeleteAttachmentAdmin endpoints to return a DeleteAttachmentResponseModel instead of returning DeleteAttachmentResponseData which contained the cipher entity.

📸 Screenshots

@github-actions
Copy link
Contributor

github-actions bot commented Feb 16, 2026

Logo
Checkmarx One – Scan Summary & Detailsbcef72f4-b262-4865-814c-4da892ba3669

New Issues (1)

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1527
detailsMethod at line 1527 of /src/Api/Vault/Controllers/CiphersController.cs gets a parameter from a user request from id. This parameter value flows ...
Attack Vector
Fixed Issues (1)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1527

@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants