From b8f5ec7c1ef87750de80fb58c5414c545ac6ad38 Mon Sep 17 00:00:00 2001 From: Yarmo Mackenbach Date: Sat, 10 Sep 2022 16:19:53 +0200 Subject: [PATCH] Fix missing input validation --- src/proxy/api/v2/index.js | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/proxy/api/v2/index.js b/src/proxy/api/v2/index.js index c16d6ae..18f7a17 100644 --- a/src/proxy/api/v2/index.js +++ b/src/proxy/api/v2/index.js @@ -177,7 +177,9 @@ router.get( // Telegram route router.get( - '/get/telegram', query('chat').isString(), + '/get/telegram', + query('user').isString(), + query('chat').isString(), async (req, res) => { if (!opts.claims.telegram.token) { return res.status(501).json({ errors: 'Telegram not enabled on server' })