Edit history

Earlier versions of Nonexistent users can be banned through /ban or API, newest first.

Current version | Edited by Rex
Changes
2. Observe a user with this ID to be banned in the activity logRemoved: ### EnvironmentRemoved: Removed: _No response_Removed: Removed: ### Logs or screenshotsRemoved: Removed: _No response_Removed: Removed: ### ChecksRemoved: Removed: - ☑ I searched existing issues.Removed: - ☑ I wrote this report in my own words, except for direct translation if needed.Removed:
Show

Nonexistent users can be banned through /ban or API

Summary

(originally reported in #411; still happening) Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log) It's also possible to write /ban <@idhere> inside the client to do the same thing While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug. specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work Edit: sorry for pinging you, idhere

Steps to reproduce

  1. Type this into your chat box /ban <@67> (or whichever number amuses you)
  2. Observe a user with this ID to be banned in the activity log
Edited by Rex
Changes
### SummaryRemoved: (originally reported in [#696](https://feedback.fluxer.com/p/411); still happening)Added: (originally reported in [#411](https://feedback.fluxer.com/p/411); still happening)Through the API you can `PUT https://api.fluxer.app/v1/users/{id}` with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log)
Show

Nonexistent users can be banned through /ban or API

Summary

(originally reported in #411; still happening) Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log) It's also possible to write /ban <@idhere> inside the client to do the same thing While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug. specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work Edit: sorry for pinging you, idhere

Steps to reproduce

  1. Type this into your chat box /ban <@67> (or whichever number amuses you)
  2. Observe a user with this ID to be banned in the activity log

Environment

No response

Logs or screenshots

No response

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.
Original by Rex
Show

Nonexistent users can be banned through /ban or API

Summary

(originally reported in #696; still happening) Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log) It's also possible to write /ban <@idhere> inside the client to do the same thing While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug. specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work Edit: sorry for pinging you, idhere

Steps to reproduce

  1. Type this into your chat box /ban <@67> (or whichever number amuses you)
  2. Observe a user with this ID to be banned in the activity log

Environment

No response

Logs or screenshots

No response

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.