Ghost/ghost
Fabien 'egg' O'Carroll b3471ab439
Improved comments API security (#15065)
refs https://github.com/TryGhost/Team/issues/1688

* Added missing/failing tests
* Refactored comments BREAD into service
* Ensured member_id is not writable, it should come from auth only
* Ensured one cannot reply to a reply
* Ensured the parent_id is not writable on edit
2022-07-25 10:41:33 +01:00
..
core Improved comments API security (#15065) 2022-07-25 10:41:33 +01:00
custom-theme-settings-service Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
domain-events Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
email-analytics-provider-mailgun Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
email-analytics-service Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
express-dynamic-redirects Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
magic-link Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
member-analytics-service Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
member-events Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
members-analytics-ingress Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
members-api Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
members-csv Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
members-events-service Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
members-importer Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
members-ssr Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
offers Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
payments Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
stripe Removed repository from component package.json files 2022-07-25 11:15:16 +02:00
verification-trigger Removed repository from component package.json files 2022-07-25 11:15:16 +02:00