Files
once-campfire/app/controllers/qr_code_controller.rb
T
Marcello Costagliola 1e61cfc8f3 Reject a QR code request that can't become a QR code
QrCodeController#show is open without signing in and decodes its id as
URL-safe base64. An id that isn't base64 raised ArgumentError, and a
URL longer than a QR code holds raised QRCodeRunTimeError, so both
answered 500 and reached error reporting as server errors. Answer them
with 400 instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LwoX7uRy5vFZSNKJhSqMSG
2026-10-06 22:53:47 +02:00

14 lines
409 B
Ruby

class QrCodeController < ApplicationController
allow_unauthenticated_access
def show
url = Base64.urlsafe_decode64(params[:id])
qr_code = RQRCode::QRCode.new(url).as_svg(viewbox: true, fill: :white, color: :black)
expires_in 1.year, public: true
render plain: qr_code, content_type: "image/svg+xml"
rescue ArgumentError, RQRCodeCore::QRCodeRunTimeError
head :bad_request
end
end