fix: reject empty guild id in oauth authorization - #1694
Closed
karmugilan28 wants to merge 1 commit into
Closed
karmugilan28 wants to merge 1 commit into
karmugilan28 wants to merge 1 commit into
Conversation
Member
|
Question: was this PR AI-generated or -assisted? |
Author
|
Sir this PR is not AI generated . This is done with the ai-assisted and not completely AI-based |
"Keep in mind that we do, under no circumstances, accept AI-generated, AI-assisted, or otherwise machine-generated contributions, for legal reasons." https://github.com/spacebarchat/server/blob/master/CONTRIBUTING.MD |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What the issue was
The OAuth2 authorization endpoint accepted an empty string (
"") forguild_idbecause the schema definition (ApplicationAuthorizeSchema) lacked a minimum length constraint.What was changed
@minLength 1JSDoc validation rule to theguild_idproperty insrc/schemas/uncategorised/ApplicationAuthorizeSchema.ts.npm run generate:schemato apply the constraint to AJV.// TODO: ensure guild_id is not an empty stringcomment fromsrc/api/routes/oauth2/authorize.tssince the route wrapper middleware now intercepts and rejects empty strings automatically.Addresses the specific TODO from #1600.