From 91b7e0c800c06afbdb3324453d29ebb7acf5306f Mon Sep 17 00:00:00 2001 From: Sipke Schoorstra Date: Thu, 31 Oct 2024 19:53:26 +0100 Subject: [PATCH] Add authorization to WorkflowInstanceHub This commit decorates the WorkflowInstanceHub class with the [Authorize] attribute to ensure that only authorized users can connect to the SignalR hub. This change improves the security of the workflow event notification system. --- .../Elsa.Workflows.Api/RealTime/Hubs/WorkflowInstanceHub.cs | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/modules/Elsa.Workflows.Api/RealTime/Hubs/WorkflowInstanceHub.cs b/src/modules/Elsa.Workflows.Api/RealTime/Hubs/WorkflowInstanceHub.cs index 835a955f7..3426c07ef 100644 --- a/src/modules/Elsa.Workflows.Api/RealTime/Hubs/WorkflowInstanceHub.cs +++ b/src/modules/Elsa.Workflows.Api/RealTime/Hubs/WorkflowInstanceHub.cs @@ -1,6 +1,7 @@ using Elsa.Workflows.Api.RealTime.Contracts; using Elsa.Workflows.Runtime.Contracts; using JetBrains.Annotations; +using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.SignalR; namespace Elsa.Workflows.Api.RealTime.Hubs; @@ -9,6 +10,7 @@ namespace Elsa.Workflows.Api.RealTime.Hubs; /// Represents a SignalR hub for receiving workflow events on the client. /// [PublicAPI] +[Authorize] public class WorkflowInstanceHub : Hub { private readonly IWorkflowRuntime _workflowRuntime;