mirror of
https://github.com/basecamp/once-campfire.git
synced 2026-08-12 10:00:42 +09:00
fix: Ensure bot can only read messages from rooms it is a member of
Added explicit RecordNotFound handling to return 404 when a bot tries to read messages from a room it's not a member of. This matches the security model used by the create action. Added tests to verify: - Bot gets 404 when trying to read from room it's not a member of - Bot can successfully read from room it IS a member of Co-authored-by: openhands <openhands@all-hands.dev>
This commit is contained in:
@@ -5,6 +5,8 @@ class Messages::ByBotsController < MessagesController
|
||||
set_room
|
||||
@messages = find_paged_messages
|
||||
render json: messages_as_json(@messages)
|
||||
rescue ActiveRecord::RecordNotFound
|
||||
head :not_found
|
||||
end
|
||||
|
||||
def create
|
||||
|
||||
@@ -93,6 +93,20 @@ class Messages::ByBotsControlleTest < ActionDispatch::IntegrationTest
|
||||
assert_response :redirect # Redirects to login
|
||||
end
|
||||
|
||||
test "index returns 404 for room bot is not a member of" do
|
||||
# bender bot is NOT a member of the designers room
|
||||
room_without_bot = rooms(:designers)
|
||||
get room_bot_messages_index_url(room_without_bot, users(:bender).bot_key)
|
||||
assert_response :not_found
|
||||
end
|
||||
|
||||
test "index works for room bot IS a member of" do
|
||||
# bender bot IS a member of watercooler
|
||||
room_with_bot = rooms(:watercooler)
|
||||
get room_bot_messages_index_url(room_with_bot, users(:bender).bot_key)
|
||||
assert_response :success
|
||||
end
|
||||
|
||||
test "regular messages index still denied for bots" do
|
||||
# The standard messages endpoint (not the bot-specific one) should still be forbidden
|
||||
get room_messages_url(@room, bot_key: users(:bender).bot_key)
|
||||
|
||||
Reference in New Issue
Block a user