summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKen_Cir <65713982+KenCir@users.noreply.github.com>2026-01-31 22:37:48 +0900
committerGitHub <noreply@github.com>2026-01-31 22:37:48 +0900
commit39362f78a675dfaf8fac7aeb6dfac0bb2f181016 (patch)
tree7178b4e34a0f087f73556ba631c8c0f56c73ad4b
parentfix(deps): update dependency tar to v7.5.7 [security] (#17104) (diff)
downloadmisskey-39362f78a675dfaf8fac7aeb6dfac0bb2f181016.tar.gz
misskey-39362f78a675dfaf8fac7aeb6dfac0bb2f181016.tar.bz2
misskey-39362f78a675dfaf8fac7aeb6dfac0bb2f181016.zip
fix(backend): inconsistent permissions for /admin/get-user-ips (#17136)
* fix(backend): inconsistent permissions for /admin/get-user-ips * Update Changelog
-rw-r--r--CHANGELOG.md1
-rw-r--r--packages/backend/src/server/api/endpoints/admin/get-user-ips.ts2
2 files changed, 2 insertions, 1 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 2147213d36..3efa0279b8 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -31,6 +31,7 @@
- JSONによるClient Information Discoveryを行うには、レスポンスの`Content-Type`ヘッダーが`application/json`である必要があります
- 従来の実装(12 February 2022版・HTML Microformat形式)も引き続きサポートされます
- Enhance: メモリ使用量を削減
+- Fix: `/admin/get-user-ips` エンドポイントのアクセス権限を管理者のみに修正
## 2025.12.2
diff --git a/packages/backend/src/server/api/endpoints/admin/get-user-ips.ts b/packages/backend/src/server/api/endpoints/admin/get-user-ips.ts
index b7781b8c99..bdd0ee6cac 100644
--- a/packages/backend/src/server/api/endpoints/admin/get-user-ips.ts
+++ b/packages/backend/src/server/api/endpoints/admin/get-user-ips.ts
@@ -13,7 +13,7 @@ export const meta = {
tags: ['admin'],
requireCredential: true,
- requireModerator: true,
+ requireAdmin: true,
kind: 'read:admin:user-ips',
res: {
type: 'array',