forge/routes/api/team.js:551:
if (!request.session.User.admin && !app.settings.get('team:create')) {
reply.code(403).send({ code: 'unauthorized', error: 'unauthorized' })
}
// execution continues from here
There's no return, so a non-admin on a platform with self-service team creation disabled gets the 403 and the handler carries straight on into the team type lookup, team creation and billing setup, then tries to reply a second time.
Haven't reproduced it: the setting is enabled on my local platform and I can't change platform settings as a non-admin, so this is from reading rather than running. Every other early exit in the same handler has its return, so it looks like an oversight.
forge/routes/api/team.js:551:There's no
return, so a non-admin on a platform with self-service team creation disabled gets the 403 and the handler carries straight on into the team type lookup, team creation and billing setup, then tries to reply a second time.Haven't reproduced it: the setting is enabled on my local platform and I can't change platform settings as a non-admin, so this is from reading rather than running. Every other early exit in the same handler has its
return, so it looks like an oversight.