Skip to content

POST /api/v1/teams keeps executing after replying 403 #8581

Description

@cstns

forge/routes/api/team.js:551:

if (!request.session.User.admin && !app.settings.get('team:create')) {
    reply.code(403).send({ code: 'unauthorized', error: 'unauthorized' })
}
// execution continues from here

There's no return, so a non-admin on a platform with self-service team creation disabled gets the 403 and the handler carries straight on into the team type lookup, team creation and billing setup, then tries to reply a second time.

Haven't reproduced it: the setting is enabled on my local platform and I can't change platform settings as a non-admin, so this is from reading rather than running. Every other early exit in the same handler has its return, so it looks like an oversight.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:apiWork on the platform APItype:bugSomething isn't working

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions