dff3668a250db7f88e1f8cd6a3a0d77b82e8aa1d
Review of the org-scoping pass found that org_id on a query filter protects the row you look up, but does nothing when a handler accepts a foreign resource ID as data and a downstream unscoped query consumes it. - AssignKey: verify key and server both belong to the org - BuildAuthorizedKeys: resolve server first, scope assignments and keys to that server's org (was honouring foreign assignment rows) - Workflows: validate TargetServerIDs on create/update and re-check at trigger time - Monitor incidents/uptime handlers: gate on org-scoped GetMonitor - GetChannels: take orgID; validate channel_ids on monitor create/update - Secret and default-step unique indexes: scope to org_id so a second org no longer hits E11000 - DeleteServer/DeleteMonitor: scope cascading deletes
Description
No description provided
9 MiB
Releases
22
agent/v1.2.13
Latest
Languages
Go
48.5%
TypeScript
47.1%
CSS
2.3%
Go Template
1.3%
Dockerfile
0.5%
Other
0.3%