diff options
author | Chris <ccbrown112@gmail.com> | 2017-12-12 17:44:01 -0600 |
---|---|---|
committer | GitHub <noreply@github.com> | 2017-12-12 17:44:01 -0600 |
commit | 03f5c939deb4a6ab2fd01639b5570799e4118bab (patch) | |
tree | 23efb69df1c355dfe7ca5b20e12fa1884d3de48d /api4/webhook.go | |
parent | e57a7667ef95ad43dd502518c0b99824a48bacf1 (diff) | |
download | chat-03f5c939deb4a6ab2fd01639b5570799e4118bab.tar.gz chat-03f5c939deb4a6ab2fd01639b5570799e4118bab.tar.bz2 chat-03f5c939deb4a6ab2fd01639b5570799e4118bab.zip |
fix PUT webhook permissions (#7970)
Diffstat (limited to 'api4/webhook.go')
-rw-r--r-- | api4/webhook.go | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/api4/webhook.go b/api4/webhook.go index 4382bac94..5146024f7 100644 --- a/api4/webhook.go +++ b/api4/webhook.go @@ -109,7 +109,7 @@ func updateIncomingHook(c *Context, w http.ResponseWriter, r *http.Request) { return } - if c.Session.UserId != updatedHook.UserId && !c.App.SessionHasPermissionToTeam(c.Session, updatedHook.TeamId, model.PERMISSION_MANAGE_OTHERS_WEBHOOKS) { + if c.Session.UserId != oldHook.UserId && !c.App.SessionHasPermissionToTeam(c.Session, updatedHook.TeamId, model.PERMISSION_MANAGE_OTHERS_WEBHOOKS) { c.LogAudit("fail - inappropriate permissions") c.SetPermissionError(model.PERMISSION_MANAGE_OTHERS_WEBHOOKS) return |