mirror of
https://github.com/HDInnovations/UNIT3D-Community-Edition.git
synced 2026-02-15 08:08:58 -06:00
fix: validate user permissions when uploading torrents via api
This commit is contained in:
@@ -101,6 +101,9 @@ class TorrentController extends BaseController
|
||||
public function store(Request $request): \Illuminate\Http\JsonResponse
|
||||
{
|
||||
$user = $request->user();
|
||||
|
||||
abort_unless($user->can_upload, 403);
|
||||
|
||||
$requestFile = $request->file('torrent');
|
||||
|
||||
if (! $request->hasFile('torrent')) {
|
||||
|
||||
Reference in New Issue
Block a user