dasboard_history: security fix, added orgId filter to dashboard version lookup

This commit is contained in:
Torkel Ödegaard
2017-06-07 14:21:40 +02:00
parent 3ba8aeb9a7
commit 46412c8475
4 changed files with 25 additions and 52 deletions

View File

@@ -65,6 +65,7 @@ func CalculateDiff(options *Options) (*Result, error) {
baseVersionQuery := models.GetDashboardVersionQuery{
DashboardId: options.Base.DashboardId,
Version: options.Base.Version,
OrgId: options.OrgId,
}
if err := bus.Dispatch(&baseVersionQuery); err != nil {
@@ -74,6 +75,7 @@ func CalculateDiff(options *Options) (*Result, error) {
newVersionQuery := models.GetDashboardVersionQuery{
DashboardId: options.New.DashboardId,
Version: options.New.Version,
OrgId: options.OrgId,
}
if err := bus.Dispatch(&newVersionQuery); err != nil {