API allows sending messages in system DMs

(#424) Bug Awaiting confirmation api dms

Summary

It is possible to send a message in a channel reserved for official system messages, the API doesn't prevent it. I'm not reporting this as a security vulnerability since this API behavior can't be used for anything harmful. Even though this is not a bug users will see, I think it's still worth fixing, as it is unintended behavior.

Steps to reproduce

  1. Send a message in any DM channel while having the network tab of the browser console opened.
  2. Copy the "fetch" of the network request related to the message.
  3. Change the URI to be https://web.fluxer.app/api/v1/channels/%3Csystem channel id>/messages. Replace the <system channel id> with the ID of the system DM channel (right click -> copy channel ID).
  4. Change the "referrer" to the same URI.
  5. (You can also modify the "body".)
  6. Send the request through the browser console. This will send a message in the system DM.

Environment (optional)

stable build 87 (28da28c), 2026-03-11 14:24:05 UTC, Chrome 144.0.0.0, Linux (x86)

Logs or screenshots (optional)

image
  • 564854958-1c78cb4d-d8a2-48b1-8ce8-96c47bcfae2f.png

    564854958-1c78cb4d-d8a2-48b1-8ce8-96c47bcfae2f.png

    885×311 | 35 kB

1 comment

Sign in with Fluxer to comment and vote.
Comment by Rex
RexSystem 1 vote
Status changed from Fixed to Awaiting confirmation
This was closed in a bulk cleanup before Fluxer V2 without being checked or fixed. It may work now, so it is waiting for someone to confirm whether the bug still happens.