2. Observe a user with this ID to be banned in the activity logRemoved: -### EnvironmentRemoved: -Removed: -_No response_Removed: -Removed: -### Logs or screenshotsRemoved: -Removed: -_No response_Removed: -Removed: -### ChecksRemoved: -Removed: -- ☑ I searched existing issues.Removed: -- ☑ I wrote this report in my own words, except for direct translation if needed.Removed: -
Show
Nonexistent users can be banned through /ban or API
Summary
(originally reported in #411; still happening)
Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log)
It's also possible to write /ban <@idhere> inside the client to do the same thing
While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug.
specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work
Edit: sorry for pinging you, idhere
Steps to reproduce
Type this into your chat box /ban <@67> (or whichever number amuses you)
Observe a user with this ID to be banned in the activity log
Edited by Rex
Changes
### SummaryRemoved: -(originally reported in [#696](https://feedback.fluxer.com/p/411); still happening)Added: +(originally reported in [#411](https://feedback.fluxer.com/p/411); still happening)Through the API you can `PUT https://api.fluxer.app/v1/users/{id}` with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log)
Show
Nonexistent users can be banned through /ban or API
Summary
(originally reported in #411; still happening)
Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log)
It's also possible to write /ban <@idhere> inside the client to do the same thing
While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug.
specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work
Edit: sorry for pinging you, idhere
Steps to reproduce
Type this into your chat box /ban <@67> (or whichever number amuses you)
Observe a user with this ID to be banned in the activity log
Environment
No response
Logs or screenshots
No response
Checks
☑ I searched existing issues.
☑ I wrote this report in my own words, except for direct translation if needed.
Original by Rex
Show
Nonexistent users can be banned through /ban or API
Summary
(originally reported in #696; still happening)
Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log)
It's also possible to write /ban <@idhere> inside the client to do the same thing
While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug.
specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work
Edit: sorry for pinging you, idhere
Steps to reproduce
Type this into your chat box /ban <@67> (or whichever number amuses you)
Observe a user with this ID to be banned in the activity log
Environment
No response
Logs or screenshots
No response
Checks
☑ I searched existing issues.
☑ I wrote this report in my own words, except for direct translation if needed.