AOSSIE-Org / AOSSIE-Org/DebateAI

[FEATURE]: /profile Elo update endpoint lets any authenticated client set arbitrary users' ratings

Open
#392 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
TypeScript
Stars
84
Forks
198
Avg merge
2d 19h
Merged PRs (30d)
30

Description

### Feature and its Use Cases

## Description
`UpdateEloAfterDebate` in `backend/controllers/profile_controller.go` (lines 352-381) reads `winnerId` and `loserId` straight from the request body and updates both users' ratings with no verification that:
- the caller was a participant in any debate,
- a debate between those users actually happened,
- the caller isn't naming themselves as winner repeatedly.

It is also a plain FindOne → `$set` read-modify-write with no transaction, so concurrent calls lose updates.

### Additional Context

## Impact
Any logged-in user can farm rating (or zero out other players) with a few `curl` calls, making the leaderboard meaningless.

## Suggested Fix
Derive winner/loser server-side from the stored debate result (the websocket/judge flow already knows the outcome) and remove the client-supplied IDs. Use an atomic update (`$inc` or optimistic concurrency on a version field).

### Code of Conduct

- [x] I have joined the [Discord server](https://discord.gg/hjUhu33uAn) and will post updates there
- [x] I have searched existing issues to avoid duplicates

Contributor guide

No contributing guide indexed for this repository

Research direction

Start in backend/controllers/profile_controller.go at UpdateEloAfterDebate (lines 352-381), then trace the websocket/judge flow and the stored debate result it uses. Review the current FindOne → $set path and verify that completion derives the outcome server-side, prevents unauthorized rating changes, and preserves concurrent updates.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, mongodb
Domain
authorization, backend, databases, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.