Fix n8n sub-dep CVE

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-03-27 08:10:57 +01:00
parent 6d0c7fe262
commit 36d517e8ce
3 changed files with 2765 additions and 63 deletions

2804
package-lock.json generated

File diff suppressed because it is too large Load Diff

View File

@@ -23,16 +23,11 @@ async function proboGraphqlRequest(
): Promise<IDataObject> { ): Promise<IDataObject> {
const credentials = await this.getCredentials('proboApi'); const credentials = await this.getCredentials('proboApi');
if (!credentials?.apiKey) {
throw new NodeApiError(this.getNode(), { message: 'API Key is required' } as JsonObject);
}
const options: IHttpRequestOptions = { const options: IHttpRequestOptions = {
method: 'POST', method: 'POST',
baseURL: `${credentials.server}`, baseURL: `${credentials.server}`,
url: apiPath, url: apiPath,
headers: { headers: {
Authorization: `Bearer ${credentials.apiKey}`,
'Content-Type': 'application/json', 'Content-Type': 'application/json',
'User-Agent': `probo-n8n-node/${version}`, 'User-Agent': `probo-n8n-node/${version}`,
}, },
@@ -44,7 +39,11 @@ async function proboGraphqlRequest(
}; };
try { try {
const response = await this.helpers.httpRequest(options); const response = await this.helpers.httpRequestWithAuthentication.call(
this,
'proboApi',
options,
);
if (response.errors && Array.isArray(response.errors) && response.errors.length > 0) { if (response.errors && Array.isArray(response.errors) && response.errors.length > 0) {
const errorMessages = response.errors.map((err: IDataObject) => const errorMessages = response.errors.map((err: IDataObject) =>
@@ -180,10 +179,6 @@ export async function proboApiMultipartRequest(
): Promise<IDataObject> { ): Promise<IDataObject> {
const credentials = await this.getCredentials('proboApi'); const credentials = await this.getCredentials('proboApi');
if (!credentials?.apiKey) {
throw new NodeApiError(this.getNode(), { message: 'API Key is required' } as JsonObject);
}
const boundary = `----n8nFormBoundary${Date.now().toString(16)}`; const boundary = `----n8nFormBoundary${Date.now().toString(16)}`;
const safeFileName = fileName const safeFileName = fileName
@@ -218,7 +213,6 @@ export async function proboApiMultipartRequest(
baseURL: `${credentials.server}`, baseURL: `${credentials.server}`,
url: '/api/console/v1/graphql', url: '/api/console/v1/graphql',
headers: { headers: {
Authorization: `Bearer ${credentials.apiKey}`,
'Content-Type': `multipart/form-data; boundary=${boundary}`, 'Content-Type': `multipart/form-data; boundary=${boundary}`,
'User-Agent': `probo-n8n-node/${version}`, 'User-Agent': `probo-n8n-node/${version}`,
}, },
@@ -226,7 +220,11 @@ export async function proboApiMultipartRequest(
}; };
try { try {
const response = await this.helpers.httpRequest(options); const response = await this.helpers.httpRequestWithAuthentication.call(
this,
'proboApi',
options,
);
if (response.errors && Array.isArray(response.errors) && response.errors.length > 0) { if (response.errors && Array.isArray(response.errors) && response.errors.length > 0) {
const errorMessages = response.errors.map((err: IDataObject) => const errorMessages = response.errors.map((err: IDataObject) =>

View File

@@ -55,7 +55,7 @@
"n8n-workflow": "*" "n8n-workflow": "*"
}, },
"devDependencies": { "devDependencies": {
"@n8n/node-cli": "^0.17.0", "@n8n/node-cli": "^0.23.1",
"eslint": "^9.39.2" "eslint": "^9.39.2"
} }
} }