From 6fbf7890cc842e1dbd3bd20ad28d01bacf24d445 Mon Sep 17 00:00:00 2001 From: Girish Ramakrishnan Date: Wed, 22 Sep 2021 12:45:11 -0700 Subject: [PATCH] operator: mailbox route has to be protected this is because operator cannot list domains --- src/server.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/server.js b/src/server.js index 030f2d759..320723f78 100644 --- a/src/server.js +++ b/src/server.js @@ -215,7 +215,7 @@ function initializeExpressSync() { router.post('/api/v1/apps/:id/configure/reverse_proxy', json, token, routes.apps.load, authorizeOperator, routes.apps.setReverseProxyConfig); router.post('/api/v1/apps/:id/configure/cert', json, token, routes.apps.load, authorizeOperator, routes.apps.setCertificate); router.post('/api/v1/apps/:id/configure/debug_mode', json, token, routes.apps.load, authorizeOperator, routes.apps.setDebugMode); - router.post('/api/v1/apps/:id/configure/mailbox', json, token, routes.apps.load, authorizeOperator, routes.apps.setMailbox); + router.post('/api/v1/apps/:id/configure/mailbox', json, token, routes.apps.load, authorizeAdmin, routes.apps.setMailbox); router.post('/api/v1/apps/:id/configure/env', json, token, routes.apps.load, authorizeOperator, routes.apps.setEnvironment); router.post('/api/v1/apps/:id/configure/data_dir', json, token, routes.apps.load, authorizeAdmin, routes.apps.setDataDir); router.post('/api/v1/apps/:id/configure/location', json, token, routes.apps.load, authorizeAdmin, routes.apps.setLocation);