ISSUE_NUMBER: GH-3
Description
The updateQuestionDetails route in routes/questionRoutes.js lacks authentication middleware, allowing unauthorized users to modify question details.
File: repositories/QuestionBankapi/routes/questionRoutes.js
Line: 14
Severity: critical
Current Behavior
The updateQuestionDetails route is accessible without authentication.
Expected Behavior
The updateQuestionDetails route should require authentication to prevent unauthorized access.
Suggested Fix
Apply the isAuthenticated middleware to the updateQuestionDetails route.
Code Context
router.put("/updateQuestionDetails/:id", updateQuestionDetails);
Additional Notes
This is a critical security vulnerability that could allow malicious users to modify question data.
ISSUE_NUMBER: GH-3
Description
The
updateQuestionDetailsroute inroutes/questionRoutes.jslacks authentication middleware, allowing unauthorized users to modify question details.File:
repositories/QuestionBankapi/routes/questionRoutes.jsLine: 14
Severity: critical
Current Behavior
The
updateQuestionDetailsroute is accessible without authentication.Expected Behavior
The
updateQuestionDetailsroute should require authentication to prevent unauthorized access.Suggested Fix
Apply the
isAuthenticatedmiddleware to theupdateQuestionDetailsroute.Code Context
Additional Notes
This is a critical security vulnerability that could allow malicious users to modify question data.