diff options
author | Unknwon <u@gogs.io> | 2016-07-17 08:33:59 +0800 |
---|---|---|
committer | Unknwon <u@gogs.io> | 2016-07-17 08:33:59 +0800 |
commit | 60110adc06ef85e533f48a52a744d43c63a818bc (patch) | |
tree | 722f5adcf7a2269563f0e9c2ed415449a607cbfb /routers/org | |
parent | 5ff2dfb23eb4f5c436d69cc86945192eb4b3d279 (diff) | |
download | gitea-60110adc06ef85e533f48a52a744d43c63a818bc.tar.gz gitea-60110adc06ef85e533f48a52a744d43c63a818bc.zip |
models/webhook: restrict deletion to be explicitly with repo and org ID
Diffstat (limited to 'routers/org')
-rw-r--r-- | routers/org/setting.go | 18 |
1 files changed, 2 insertions, 16 deletions
diff --git a/routers/org/setting.go b/routers/org/setting.go index a938581c61..7900613b77 100644 --- a/routers/org/setting.go +++ b/routers/org/setting.go @@ -7,8 +7,6 @@ package org import ( "strings" - "github.com/Unknwon/com" - "github.com/gogits/gogs/models" "github.com/gogits/gogs/modules/auth" "github.com/gogits/gogs/modules/base" @@ -142,18 +140,6 @@ func Webhooks(ctx *context.Context) { ctx.Data["BaseLink"] = ctx.Org.OrgLink ctx.Data["Description"] = ctx.Tr("org.settings.hooks_desc") - // Delete web hook. - remove := com.StrTo(ctx.Query("remove")).MustInt64() - if remove > 0 { - if err := models.DeleteWebhook(remove); err != nil { - ctx.Handle(500, "DeleteWebhook", err) - return - } - ctx.Flash.Success(ctx.Tr("repo.settings.remove_hook_success")) - ctx.Redirect(ctx.Org.OrgLink + "/settings/hooks") - return - } - ws, err := models.GetWebhooksByOrgID(ctx.Org.Organization.Id) if err != nil { ctx.Handle(500, "GetWebhooksByOrgId", err) @@ -165,8 +151,8 @@ func Webhooks(ctx *context.Context) { } func DeleteWebhook(ctx *context.Context) { - if err := models.DeleteWebhook(ctx.QueryInt64("id")); err != nil { - ctx.Flash.Error("DeleteWebhook: " + err.Error()) + if err := models.DeleteWebhookByOrgID(ctx.Org.Organization.Id, ctx.QueryInt64("id")); err != nil { + ctx.Flash.Error("DeleteWebhookByOrgID: " + err.Error()) } else { ctx.Flash.Success(ctx.Tr("repo.settings.webhook_deletion_success")) } |