Add authorization to WorkflowInstanceHub

This commit decorates the WorkflowInstanceHub class with the [Authorize] attribute to ensure that only authorized users can connect to the SignalR hub. This change improves the security of the workflow event notification system.
This commit is contained in:
Sipke Schoorstra 2024-10-31 19:53:26 +01:00
parent c3b6decf66
commit 91b7e0c800

View file

@ -1,6 +1,7 @@
using Elsa.Workflows.Api.RealTime.Contracts;
using Elsa.Workflows.Runtime.Contracts;
using JetBrains.Annotations;
using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.SignalR;
namespace Elsa.Workflows.Api.RealTime.Hubs;
@ -9,6 +10,7 @@ namespace Elsa.Workflows.Api.RealTime.Hubs;
/// Represents a SignalR hub for receiving workflow events on the client.
/// </summary>
[PublicAPI]
[Authorize]
public class WorkflowInstanceHub : Hub<IWorkflowInstanceClient>
{
private readonly IWorkflowRuntime _workflowRuntime;