From c1a9095ad4fa37c5ca729b6f900d4aaca09496cc Mon Sep 17 00:00:00 2001 From: Nicola Soranzo Date: Sun, 10 Mar 2019 12:51:50 +0000 Subject: [PATCH] Restrict loading of JSON files on the server via the workflow API to Galaxy admins Fix https://github.com/galaxyproject/security/issues/29 --- lib/galaxy/webapps/galaxy/api/workflows.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/lib/galaxy/webapps/galaxy/api/workflows.py b/lib/galaxy/webapps/galaxy/api/workflows.py index fae15d64f0f..dbe5dd5ce4f 100644 --- a/lib/galaxy/webapps/galaxy/api/workflows.py +++ b/lib/galaxy/webapps/galaxy/api/workflows.py @@ -278,6 +278,8 @@ class WorkflowsAPIController(BaseAPIController, UsesStoredWorkflowMixin, UsesAnn raise exceptions.RequestParameterInvalidException(message) if 'installed_repository_file' in payload: + if not trans.user_is_admin: + raise exceptions.AdminRequiredException() installed_repository_file = payload.get('installed_repository_file', '') if not os.path.exists(installed_repository_file): raise exceptions.MessageException("Repository file '%s' not found.")