Summary
When hitting the endpoint for
List guild audit logs using
Authorization: Bot {token} in the header, I receive this:
{"code":"ACCESS_DENIED","message":"You don't have access to this resource or feature."}%
When I use my user token I receive a proper response:
{
"audit_log_entries": [
{ ... },
{ ... }
]
}
I have ensured that the bot has view permissions, and even tested administrator permissions:
image
Steps to reproduce
- send CURL using bot token:
curl -H "Authorization: Bot {bot_token}" \
"https://web.fluxer.app/api/v1/guilds/{community_id}/audit-logs?limit=20"
- send CURL using user token:
curl -H "Authorization: {user_token}" \
"https://web.fluxer.app/api/v1/guilds/{community_id}/audit-logs?limit=20"
- Observations: Bot receives
ACCESS_DENIED, user receives correct response.
Environment (optional)
- Commit/Tag: latest web
- OS: tested on Arch & macOS both in terminal
Logs or screenshots (optional)
❯ curl -H "Authorization: Bot {redacted}" \
"https://web.fluxer.app/api/v1/guilds/{redacted}/audit-logs?limit=20"
{"code":"ACCESS_DENIED","message":"You don't have access to this resource or feature."}%
❯ curl -H "Authorization: {redacted}" \
"https://web.fluxer.app/api/v1/guilds/{redacted}/audit-logs?limit=20"
{"audit_log_entries":[{"id":"1474392578898948975","action_type":24,"user_id":"1470926459688796802","target_id":"1473978252332421496","changes":[{"key":"nick","old_value":null,"new_value":"Bot"}]}]}
5 comments
Comment by @pekempy
Comment by @BenjaminUrquhart
audit-logendpoint uses an auth mode that explicitly disallows bot users. https://github.com/fluxerapp/fluxer/blob/4f5704fa1f6426d65a12ee5fef13c0104669d08e/packages/api/src/guild/controllers/GuildAuditLogController.tsx#L35 https://github.com/fluxerapp/fluxer/blob/4f5704fa1f6426d65a12ee5fef13c0104669d08e/packages/api/src/middleware/AuthMiddleware.tsx#L57-L66Comment by @pekempy
Comment by @pekempy
554785965-3844fa44-d4e4-47b5-967b-393b3621f605.png
1002×124 | 46 kB
Comment by @pekempy