aboutsummaryrefslogtreecommitdiffstats
path: root/apps/workflowengine/src
diff options
context:
space:
mode:
authorMax <max@nextcloud.com>2023-03-01 13:03:47 +0100
committerMax <max@nextcloud.com>2023-03-01 13:03:47 +0100
commit95a674e238eaf2685b85709ec233f6241abbc548 (patch)
tree66845105aa1a976d0e8c7d62b7eaec5d3bfcb1e8 /apps/workflowengine/src
parent416efc12d6a0e535468082dfb9f88c17b7050236 (diff)
downloadnextcloud-server-95a674e238eaf2685b85709ec233f6241abbc548.tar.gz
nextcloud-server-95a674e238eaf2685b85709ec233f6241abbc548.zip
fix: treat text app session parameters as sensitive values
* `PublicSessionController create` receives a share token. * The others receive the parameters for a text session: `document_id`, `session_id`, `session_token`. Even though these are relatively short lived they could be used to retrieve content from the document when leaked. Signed-off-by: Max <max@nextcloud.com>
Diffstat (limited to 'apps/workflowengine/src')
0 files changed, 0 insertions, 0 deletions