-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Threads integration updating verifyLInk api / answerAbos and tiktok api v2 #289
Conversation
const threadsAbos = async (idPost, id, userName) => { | ||
try { | ||
var followers = 0 | ||
var campaign_link = await CampaignLink.findOne({ idPost }).lean() |
Check failure
Code scanning / CodeQL
Database query built from user-controlled sources High
user-provided value
@@ -1393,4 +1396,11 @@ | |||
router.get('/Tiktok/ProfilPrivacy', verifyAuth, ProfilPrivacy) | |||
|
|||
|
|||
router.get('/check/threads-account',verifyAuth,checkThreads) |
Check failure
Code scanning / CodeQL
Missing rate limiting High
authorization
@@ -1393,4 +1396,11 @@ | |||
router.get('/Tiktok/ProfilPrivacy', verifyAuth, ProfilPrivacy) | |||
|
|||
|
|||
router.get('/check/threads-account',verifyAuth,checkThreads) |
Check failure
Code scanning / CodeQL
Missing rate limiting High
a database access
@@ -1393,4 +1396,11 @@ | |||
router.get('/Tiktok/ProfilPrivacy', verifyAuth, ProfilPrivacy) | |||
|
|||
|
|||
router.get('/check/threads-account',verifyAuth,checkThreads) | |||
|
|||
router.get('/add/threads-account', verifyAuth, addThreadsAccount) |
Check failure
Code scanning / CodeQL
Missing rate limiting High
authorization
@@ -1393,4 +1396,11 @@ | |||
router.get('/Tiktok/ProfilPrivacy', verifyAuth, ProfilPrivacy) | |||
|
|||
|
|||
router.get('/check/threads-account',verifyAuth,checkThreads) | |||
|
|||
router.get('/add/threads-account', verifyAuth, addThreadsAccount) |
Check failure
Code scanning / CodeQL
Missing rate limiting High
a database access
This route handler performs
a database access
|
||
exports.verifyThread = async (idPost, threads_id) => { | ||
try { | ||
const res = await axios.get(`https://www.threads.net/t/${idPost}`); |
Check failure
Code scanning / CodeQL
Server-side request forgery Critical
URL
user-provided value
|
||
router.get('/add/threads-account', verifyAuth, addThreadsAccount) | ||
|
||
router.delete('/remove/threads-account/:id', verifyAuth, idThreadsAccountValidation,removeThreadsAccount) |
Check failure
Code scanning / CodeQL
Missing rate limiting High
authorization
|
||
router.get('/add/threads-account', verifyAuth, addThreadsAccount) | ||
|
||
router.delete('/remove/threads-account/:id', verifyAuth, idThreadsAccountValidation,removeThreadsAccount) |
Check failure
Code scanning / CodeQL
Missing rate limiting High
a database access
This route handler performs
Tiktok api v2 integration instead of the v1 version that will become deprecated.
adding verifyThread function in verifyLink api to check the thread Url from client
adding threadsAbos function in aswerAbos to fetch user account followers_count
adding check/insta api to check if a user has an instagram account so we'll allow him to add a threads account