From 760750de05a5518d296d87fc6890682ed1b2e0bb Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Tue, 26 Aug 2025 15:46:45 +0000 Subject: [PATCH] Add authorization attribute to ConfigurationController for security Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com> --- Server/Controllers/ConfigurationController.cs | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Server/Controllers/ConfigurationController.cs b/Server/Controllers/ConfigurationController.cs index 93a3e7a..26f154a 100644 --- a/Server/Controllers/ConfigurationController.cs +++ b/Server/Controllers/ConfigurationController.cs @@ -1,3 +1,4 @@ +using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Mvc; using ShiftScheduler.Services; using ShiftScheduler.Shared; @@ -7,6 +8,7 @@ namespace ShiftScheduler.Server.Controllers { [ApiController] [Route("api/[controller]")] + [Authorize(Policy = "AllowedEmails")] public class ConfigurationController : ControllerBase { private readonly IConfigurationService _configurationService;