Skip to content

[PM-25820] Return DeleteAttachmentResponseModel from cipher attachment delete endpoints#7013

Open
gbubemismith wants to merge 1 commit intomainfrom
vault/PM-25820-cipher-response-model
Open

[PM-25820] Return DeleteAttachmentResponseModel from cipher attachment delete endpoints#7013
gbubemismith wants to merge 1 commit intomainfrom
vault/PM-25820-cipher-response-model

Conversation

@gbubemismith
Copy link
Contributor

🎟️ Tracking

https://bitwarden.atlassian.net/browse/PM-25820

📔 Objective

Updates the DeleteAttachment and DeleteAttachmentAdmin endpoints to return a DeleteAttachmentResponseModel instead of returning DeleteAttachmentResponseData which contained the cipher entity.

📸 Screenshots

@sonarqubecloud
Copy link

@github-actions
Copy link
Contributor

Logo
Checkmarx One – Scan Summary & Details88abdfce-72dc-4d26-823c-88208ad3aca6

New Issues (1)

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1527
detailsMethod at line 1527 of /src/Api/Vault/Controllers/CiphersController.cs gets a parameter from a user request from id. This parameter value flows ...
Attack Vector
Fixed Issues (1)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1527

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant