Skip to content

Commit

Permalink
Merge pull request #496 from akhandpratapsingh88/Akhand@hcl-Accelerat…
Browse files Browse the repository at this point in the history
…or-security-vulnerabilities-fixes

Fix for Important Security vulnerabilities
  • Loading branch information
santhoshb-msft authored May 18, 2023
2 parents ebe2fde + 477e29a commit 6ed40de
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 0 deletions.
2 changes: 2 additions & 0 deletions src/AdminSite/Controllers/ApplicationLogController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -4,11 +4,13 @@
using Marketplace.SaaS.Accelerator.DataAccess.Contracts;
using Marketplace.SaaS.Accelerator.DataAccess.Entities;
using Marketplace.SaaS.Accelerator.Services.Services;
using Marketplace.SaaS.Accelerator.Services.Utilities;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.Logging;

namespace Marketplace.SaaS.Accelerator.AdminSite.Controllers;

[ServiceFilter(typeof(KnownUserAttribute))]
public class ApplicationLogController : BaseController
{
private readonly ILogger<ApplicationLogController> logger;
Expand Down
7 changes: 7 additions & 0 deletions src/CustomerSite/Controllers/HomeController.cs
Original file line number Diff line number Diff line change
Expand Up @@ -404,6 +404,13 @@ public IActionResult SubscriptionLogDetail(Guid subscriptionId)
{
if (this.User.Identity.IsAuthenticated)
{
// Validate subscription from same customer
var subscriptionDetail = this.subscriptionService.GetPartnerSubscription(this.CurrentUserEmailAddress, subscriptionId).FirstOrDefault();
if(subscriptionDetail == null)
{
return this.RedirectToAction(nameof(this.Index));
}

List<SubscriptionAuditLogs> subscriptionAudit = new List<SubscriptionAuditLogs>();
subscriptionAudit = this.subscriptionLogRepository.GetSubscriptionBySubscriptionId(subscriptionId).ToList();
return this.PartialView(subscriptionAudit);
Expand Down

0 comments on commit 6ed40de

Please sign in to comment.