api: `audit-log` endpoint does not work with bot tokens

(#245) Bug Fixed api

Summary

When hitting the endpoint for List guild audit logs using Authorization: Bot {token} in the header, I receive this:
{"code":"ACCESS_DENIED","message":"You don't have access to this resource or feature."}%
When I use my user token I receive a proper response:
{
    "audit_log_entries": [
        { ... },
        { ... }
    ]
}
I have ensured that the bot has view permissions, and even tested administrator permissions: image

Steps to reproduce

  1. send CURL using bot token:
    curl -H "Authorization: Bot {bot_token}" \
         "https://web.fluxer.app/api/v1/guilds/{community_id}/audit-logs?limit=20"
  2. send CURL using user token:
    curl -H "Authorization: {user_token}" \
         "https://web.fluxer.app/api/v1/guilds/{community_id}/audit-logs?limit=20"
  3. Observations: Bot receives ACCESS_DENIED, user receives correct response.

Environment (optional)

  • Commit/Tag: latest web
  • OS: tested on Arch & macOS both in terminal

Logs or screenshots (optional)

❯ curl -H "Authorization: Bot {redacted}" \
     "https://web.fluxer.app/api/v1/guilds/{redacted}/audit-logs?limit=20"

{"code":"ACCESS_DENIED","message":"You don't have access to this resource or feature."}%
❯ curl -H "Authorization: {redacted}" \
     "https://web.fluxer.app/api/v1/guilds/{redacted}/audit-logs?limit=20"

{"audit_log_entries":[{"id":"1474392578898948975","action_type":24,"user_id":"1470926459688796802","target_id":"1473978252332421496","changes":[{"key":"nick","old_value":null,"new_value":"Bot"}]}]}
  • 552716967-ff3cabbb-ad7b-4c6d-b7e9-d6bd90c83ae1.png

    552716967-ff3cabbb-ad7b-4c6d-b7e9-d6bd90c83ae1.png

    595×118 | 23 kB

5 comments

Sign in with Fluxer to comment and vote.
Comment by @pekempy
RexSystem 1 vote originally by @pekempy on GitHub OP
Noticed similar behaviour setting a bot's community image - it does not update, however the exact same code with user token does work.
Comment by @BenjaminUrquhart
RexSystem 1 vote originally by @BenjaminUrquhart on GitHub
Comment by @pekempy
RexSystem 1 vote originally by @pekempy on GitHub OP
Looking through how things are handled, it seems the audit-log endpoint uses an auth mode that explicitly disallows bot users.
I wonder if there's any reason for this, given that we can granuarly set permissions to grant a bot access to it
Comment by @pekempy
RexSystem 1 vote edited originally by @pekempy on GitHub OP
@BenjaminUrquhart image
  • 554785965-3844fa44-d4e4-47b5-967b-393b3621f605.png

    554785965-3844fa44-d4e4-47b5-967b-393b3621f605.png

    1002×124 | 46 kB

Comment by @pekempy
RexSystem 1 vote originally by @pekempy on GitHub OP
Issue has been resolved, both audit log and setting bots avatar per-server now working