Skip to content

Commit ab9dffa

Browse files
authored
Merge pull request #181 from pdsinterop/fix/CLN-005
Fix CWE-650 (Trusting HTTP Permission Methods on the Server Side) on the /revoke endpoint
2 parents b1b22ab + eba5fbf commit ab9dffa

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

solid/appinfo/routes.php

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,9 @@
1111
'routes' => [
1212
['name' => 'page#profile', 'url' => '/@{userId}/', 'verb' => 'GET'],
1313
['name' => 'page#approval', 'url' => '/sharing/{clientId}', 'verb' => 'GET'],
14-
['name' => 'page#handleRevoke', 'url' => '/revoke/{clientId}', 'verb' => 'GET'],
14+
['name' => 'page#handleRevoke', 'url' => '/revoke/{clientId}', 'verb' => 'DELETE'],
15+
['name' => 'page#handleRevoke', 'url' => '/revoke/{clientId}', 'verb' => 'POST'],
16+
1517
['name' => 'page#handleApproval', 'url' => '/sharing/{clientId}', 'verb' => 'POST'],
1618
['name' => 'page#dataJson', 'url' => '/@{userId}/data.json', 'verb' => 'GET' ],
1719
['name' => 'page#customscheme', 'url' => '/customscheme', 'verb' => 'GET'],

0 commit comments

Comments
 (0)