mirror of
https://github.com/basecamp/once-campfire.git
synced 2026-10-06 06:40:07 +09:00
fix: Align create and index to both return 404 for non-member rooms
Both create and index now return HTTP 404 Not Found when a bot tries to access a room it's not a member of. This is consistent with REST API security best practices (not revealing resource existence) and ensures read and write permissions are handled identically. Changed create action to no longer call super (which rendered HTML) and instead directly handle the request with proper JSON API error responses. Added test to verify create returns 404 for non-member rooms. Co-authored-by: openhands <openhands@all-hands.dev>
This commit is contained in:
@@ -10,8 +10,13 @@ class Messages::ByBotsController < MessagesController
|
||||
end
|
||||
|
||||
def create
|
||||
super
|
||||
set_room
|
||||
@message = @room.messages.create_with_attachment!(message_params)
|
||||
@message.broadcast_create
|
||||
deliver_webhooks_to_bots
|
||||
head :created, location: message_url(@message)
|
||||
rescue ActiveRecord::RecordNotFound
|
||||
head :not_found
|
||||
end
|
||||
|
||||
private
|
||||
|
||||
Reference in New Issue
Block a user