Reject a QR code request that can't become a QR code

QrCodeController#show is open without signing in and decodes its id as
URL-safe base64. An id that isn't base64 raised ArgumentError, and a
URL longer than a QR code holds raised QRCodeRunTimeError, so both
answered 500 and reached error reporting as server errors. Answer them
with 400 instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LwoX7uRy5vFZSNKJhSqMSG
This commit is contained in:
Marcello Costagliola
2026-10-06 22:53:47 +02:00
parent 32b4144b52
commit 1e61cfc8f3
2 changed files with 16 additions and 0 deletions
@@ -12,4 +12,18 @@ class QrCodeControllerTest < ActionDispatch::IntegrationTest
assert_equal 1.year, response.cache_control[:max_age].to_i
assert response.cache_control[:public]
end
test "show rejects an id that isn't base64" do
get qr_code_path("not-base64!")
assert_response :bad_request
end
test "show rejects a URL too long for a QR code" do
id = Base64.urlsafe_encode64("http://example.com/" + "a" * 3000)
get qr_code_path(id)
assert_response :bad_request
end
end