From f05c7d79e391cbdc5e13ae89f0d980e16fd016f7 Mon Sep 17 00:00:00 2001 From: Shaun Walker Date: Tue, 12 May 2020 14:31:18 -0400 Subject: [PATCH] add security to site template API --- Oqtane.Server/Controllers/SiteTemplateController.cs | 3 +++ 1 file changed, 3 insertions(+) diff --git a/Oqtane.Server/Controllers/SiteTemplateController.cs b/Oqtane.Server/Controllers/SiteTemplateController.cs index 2f709fb1..c63170c1 100644 --- a/Oqtane.Server/Controllers/SiteTemplateController.cs +++ b/Oqtane.Server/Controllers/SiteTemplateController.cs @@ -1,7 +1,9 @@ using System.Collections.Generic; +using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Mvc; using Oqtane.Models; using Oqtane.Repository; +using Oqtane.Shared; namespace Oqtane.Controllers { @@ -17,6 +19,7 @@ namespace Oqtane.Controllers // GET: api/ [HttpGet] + [Authorize(Roles = Constants.HostRole)] public IEnumerable Get() { return _siteTemplates.GetSiteTemplates();