nuclei-templates/http/token-spray/api-monday.yaml

34 lines
769 B
YAML

id: api-monday
info:
name: Monday API Test
author: daffainfo
severity: info
description: Programmatically access and update data inside a monday.com account
reference:
- https://api.developer.monday.com/docs
- https://github.com/daffainfo/all-about-apikey/tree/main/monday
tags: token-spray,monday
metadata:
max-request: 1
self-contained: true
http:
- raw:
- |
POST https://api.monday.com/v2 HTTP/1.1
Host: api.monday.com
Authorization: {{token}}
Content-Type: application/json
{"query": "query { me { is_guest created_at name id}}"}
matchers:
- type: word
part: body
words:
- '"me"'
- '"name"'
- '"account_id"'
condition: and