-
- Downloads
Merge branch 'security-10-4-todo-api-reveals-sensitive-information' into 'security-10-4'
Restrict Todo API mark_as_done endpoint to the user's todos only
Showing
- changelogs/unreleased/security-10-4-todo-api-reveals-sensitive-information.yml 5 additions, 0 deletions.../security-10-4-todo-api-reveals-sensitive-information.yml
- lib/api/todos.rb 1 addition, 1 deletionlib/api/todos.rb
- lib/api/v3/todos.rb 1 addition, 1 deletionlib/api/v3/todos.rb
- spec/requests/api/todos_spec.rb 6 additions, 0 deletionsspec/requests/api/todos_spec.rb
- spec/requests/api/v3/todos_spec.rb 6 additions, 0 deletionsspec/requests/api/v3/todos_spec.rb
Please register or sign in to comment