Merge pull request from GHSA-7pxq-6xx9-xpgm
* fix: fix improper authorization when accessing with third-party application * refactor: refactor type definitions * fix: get rid of unnecessary access limitation * enhance: サードパーティアプリケーションがWebsocket APIを使えるように * fix: add missing parentheses * Revert "fix(backend): add missing kind definition for admin endpoints to improve security" This reverts commit 51500532. * frontend: 翻訳の抜けを訂正, read:adminとwrite:adminはアクセス発行トークンのデフォルトでは非表示にする * enhance(test): misskey-ghsa-7pxq-6xx9-xpgmに関するテストを追加 * enhance(test): Websocket APIに対するテストも追加 * enhance(refactor): `@/misc/api-permissions.ts`を`misskey-js/permissions`に統合 * fix(frontend): アクセストークン発行UIで全ての権限を有効にした際、管理者用APIへのアクセスも許可してしまう問題を修正 * enhance(backend): Websocketの接続に最低限必要な権限を変更 * fix(backend): `/api/admin/meta`をサードパーティアプリケーションからはアクセスできないように * fix(backend): エンドポイントにアクセスするために必要な権限を変更 * fix(frontend/locale): Add missing type declaration * chore: update `misskey-js/src/autogen` --------- Co-authored-by:tamaina <tamaina@hotmail.co.jp>
Showing
- CHANGELOG.md 0 additions, 1 deletionCHANGELOG.md
- locales/index.d.ts 49 additions, 0 deletionslocales/index.d.ts
- locales/ja-JP.yml 49 additions, 0 deletionslocales/ja-JP.yml
- packages/backend/src/misc/api-permissions.ts 0 additions, 40 deletionspackages/backend/src/misc/api-permissions.ts
- packages/backend/src/server/api/ApiCallService.ts 2 additions, 1 deletionpackages/backend/src/server/api/ApiCallService.ts
- packages/backend/src/server/api/StreamingApiServerService.ts 4 additions, 0 deletionspackages/backend/src/server/api/StreamingApiServerService.ts
- packages/backend/src/server/api/endpoints.ts 19 additions, 1 deletionpackages/backend/src/server/api/endpoints.ts
- packages/backend/src/server/api/endpoints/admin/abuse-user-reports.ts 1 addition, 2 deletions...kend/src/server/api/endpoints/admin/abuse-user-reports.ts
- packages/backend/src/server/api/endpoints/admin/accounts/create.ts 1 addition, 1 deletion...backend/src/server/api/endpoints/admin/accounts/create.ts
- packages/backend/src/server/api/endpoints/admin/accounts/delete.ts 1 addition, 2 deletions...backend/src/server/api/endpoints/admin/accounts/delete.ts
- packages/backend/src/server/api/endpoints/admin/accounts/find-by-email.ts 1 addition, 2 deletions.../src/server/api/endpoints/admin/accounts/find-by-email.ts
- packages/backend/src/server/api/endpoints/admin/ad/create.ts 1 addition, 2 deletionspackages/backend/src/server/api/endpoints/admin/ad/create.ts
- packages/backend/src/server/api/endpoints/admin/ad/delete.ts 1 addition, 2 deletionspackages/backend/src/server/api/endpoints/admin/ad/delete.ts
- packages/backend/src/server/api/endpoints/admin/ad/list.ts 1 addition, 2 deletionspackages/backend/src/server/api/endpoints/admin/ad/list.ts
- packages/backend/src/server/api/endpoints/admin/ad/update.ts 1 addition, 2 deletionspackages/backend/src/server/api/endpoints/admin/ad/update.ts
- packages/backend/src/server/api/endpoints/admin/announcements/create.ts 1 addition, 2 deletions...nd/src/server/api/endpoints/admin/announcements/create.ts
- packages/backend/src/server/api/endpoints/admin/announcements/delete.ts 1 addition, 2 deletions...nd/src/server/api/endpoints/admin/announcements/delete.ts
- packages/backend/src/server/api/endpoints/admin/announcements/list.ts 1 addition, 2 deletions...kend/src/server/api/endpoints/admin/announcements/list.ts
- packages/backend/src/server/api/endpoints/admin/announcements/update.ts 1 addition, 2 deletions...nd/src/server/api/endpoints/admin/announcements/update.ts
- packages/backend/src/server/api/endpoints/admin/avatar-decorations/create.ts 1 addition, 2 deletions...c/server/api/endpoints/admin/avatar-decorations/create.ts
Loading
Please register or sign in to comment