Nonexistent users can be banned through /ban or API

(#622) Bug Awaiting confirmation api moderation

Summary

(originally reported in #411; still happening) Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log) It's also possible to write /ban <@idhere> inside the client to do the same thing While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug. specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work Edit: sorry for pinging you, idhere

Steps to reproduce

  1. Type this into your chat box /ban <@67> (or whichever number amuses you)
  2. Observe a user with this ID to be banned in the activity log

Merged posts

These posts were merged into this one. Their comments are now part of the conversation below, marked with where they came from.

Merged from #411 Nonexistent users can be banned through /ban or API

RexSystemoriginally by @TheKodeToad on GitHub

Report details

Summary

Through the API you can PUT https://api.fluxer.app/v1/users/{id} with a totally made-up ID* and the ban will work and persist (showing in the ban list and audit log) It's also possible to write /ban <@idhere> inside the client to do the same thing While this seems relatively harmless it could be annoying having the ban list cluttered by e.g. accidentally pasting message IDs. I also don't think there's any reason to ban deleted/non-existent users and it does feel like a bug. specifically, it seems like anything matching `^(0|[1-9][0-9])$` would work Edit: sorry for pinging you, idhere

Steps to reproduce

  1. Type this into your chat box /ban <@67> (or whichever number amuses you)
  2. Observe a user with this ID to be banned in the activity log

1 comment

Sign in with Fluxer to comment and vote.
Comment by Rex
RexSystem 1 vote
Status changed from Fixed to Awaiting confirmation
This was closed in a bulk cleanup before Fluxer V2 without being checked or fixed. It may work now, so it is waiting for someone to confirm whether the bug still happens.