[image](https://feedback.fluxer.com/p/424#f-414)Removed: -### ChecksRemoved: -Removed: -- ☑ I searched for existing issues and didn't find a duplicate.Removed: -
Show
API allows sending messages in system DMs
Summary
It is possible to send a message in a channel reserved for official system messages, the API doesn't prevent it. I'm not reporting this as a security vulnerability since this API behavior can't be used for anything harmful.
Even though this is not a bug users will see, I think it's still worth fixing, as it is unintended behavior.
Steps to reproduce
Send a message in any DM channel while having the network tab of the browser console opened.
Copy the "fetch" of the network request related to the message.
Change the URI to be https://web.fluxer.app/api/v1/channels/%3Csystem channel id>/messages. Replace the <system channel id> with the ID of the system DM channel (right click -> copy channel ID).
Change the "referrer" to the same URI.
(You can also modify the "body".)
Send the request through the browser console. This will send a message in the system DM.
It is possible to send a message in a channel reserved for official system messages, the API doesn't prevent it. I'm not reporting this as a security vulnerability since this API behavior can't be used for anything harmful.
Even though this is not a bug users will see, I think it's still worth fixing, as it is unintended behavior.
Steps to reproduce
Send a message in any DM channel while having the network tab of the browser console opened.
Copy the "fetch" of the network request related to the message.
Change the URI to be https://web.fluxer.app/api/v1/channels/%3Csystem channel id>/messages. Replace the <system channel id> with the ID of the system DM channel (right click -> copy channel ID).
Change the "referrer" to the same URI.
(You can also modify the "body".)
Send the request through the browser console. This will send a message in the system DM.