Security Fix 10: BoardTitleRESTBleed.

Thanks to [Joshua Rogers](https://joshua.hu) of [Aisle Research](https://aisle.com) and xet7.
This commit is contained in:
Lauri Ojansivu 2026-01-18 19:55:48 +02:00
parent 8c0b4f79d8
commit 545566f566

View file

@ -2433,8 +2433,8 @@ if (Meteor.isServer) {
*/
JsonRoutes.add('PUT', '/api/boards/:boardId/title', function(req, res) {
try {
Authentication.checkUserId(req.userId);
const boardId = req.params.boardId;
Authentication.checkBoardWriteAccess(req.userId, boardId);
const title = req.body.title;
Boards.direct.update({ _id: boardId }, { $set: { title } });