misc_pterodactyl-panel/app
Dane Everitt f0ac0725b6
[Security] Don't return all servers on the system when not a root admin and admin level servers are requested
Cleaned up the API endpoint by simplifying the logic and adds test case to cover this bug.

If you ever need to list _all_ of the servers on the system you should be using the application API endpoint for the servers most likely.
2020-07-26 10:43:46 -07:00
..
Console cs fix 2020-06-28 15:43:44 -07:00
Contracts Code cleanup & fix frontend searching servers; closes #2100 2020-07-06 21:25:00 -07:00
Events Send an email when a server is marked as installed (#1213) 2018-07-01 14:34:40 -07:00
Exceptions Always return the status code from the daemon if possible 2020-07-18 10:23:28 -07:00
Extensions Better S3 backup generation support 2020-05-03 20:49:09 -07:00
Helpers Remove old Theme::js calls in blade layouts. Persist checkboxes, Server Owner, Node, Default Allocation, and Additional Allocations on servers/new.blade.php 2020-04-11 13:56:03 -06:00
Http [Security] Don't return all servers on the system when not a root admin and admin level servers are requested 2020-07-26 10:43:46 -07:00
Jobs Add basic support for backups via the scheduled tasks system 2020-04-19 19:43:41 -07:00
Models [Security] Don't return all servers on the system when not a root admin and admin level servers are requested 2020-07-26 10:43:46 -07:00
Notifications Fix Subuser welcome email 2020-05-08 19:31:20 -04:00
Observers close #840 2017-12-30 20:25:04 -06:00
Policies Fix authorization checking for subusers 2020-03-28 16:18:56 -07:00
Providers Code cleanup & fix frontend searching servers; closes #2100 2020-07-06 21:25:00 -07:00
Repositories Always return the status code from the daemon if possible 2020-07-18 10:23:28 -07:00
Rules Format files 2019-09-05 21:32:57 -07:00
Services Merge branch 'develop' into feature/server-mounts 2020-07-11 12:29:30 -06:00
Traits Daemon secret is not a thing anymore 2019-12-15 18:31:15 -08:00
Transformers Update allocations to support ids; protect endpoints; support notes 2020-07-09 20:36:08 -07:00
helpers.php Remove any confusing legacy sizing files; everything in the panel is true MB (1000) not MiB 2020-05-08 21:13:39 -07:00