Don't trust Webhook data
This commit is contained in:
parent
bc3252b1f6
commit
8e4843a06c
2
main.py
2
main.py
@ -141,7 +141,7 @@ def webhook_receiver():
|
||||
elif triggercode.startswith('USERGROUP_'):
|
||||
with Connection(ldap_server, config.LDAP_BIND_USER, config.LDAP_BIND_PASSWORD) as ldap_conn:
|
||||
dolibarr_group = dolibarr_client.call_get_api(f"users/groups/{obj['id']}")
|
||||
manage_group_extra_fields(ldap_conn, obj)
|
||||
manage_group_extra_fields(ldap_conn, dolibarr_group)
|
||||
else:
|
||||
abort(400)
|
||||
return "", 204
|
||||
|
Loading…
x
Reference in New Issue
Block a user