AOSSIE-Org / AOSSIE-Org/DebateAI

[BUG]: No Validation room type when creating a debate room

Aperta Adatta ai principianti
#492 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub
bug
Lingua principale
TypeScript
Stelle
84
Fork
198
Merge medio
2g 19h
PR unite (30g)
30

Descrizione

### Bug Description

he POST /rooms endpoint accepts any non-empty value for the room type. Although the supported room types are public, private, and invite, unsupported values such as "banana" are accepted and stored successfully.
This allows invalid room data to enter the application and may cause unexpected behavior in room browsing, filtering, matchmaking, and access-control logic.

The backend should validate the supplied room type against the supported values and return 400 Bad Request when the value is invalid. This fix only requires backend validation and does not require a database schema change.

### Steps to Reproduce

1. Start the DebateAI backend server.

2. Sign in and obtain a valid access token.

3. Open Git Bash and define the API URL and token:
api="http://localhost:1313"
token="PASTE_ACCESS_TOKEN_HERE"

4. Send a room-creation request with an unsupported type:
curl.exe -i -X POST "$api/rooms" \
-H "Authorization: Bearer $token" \
-H "Content-Type: application/json" \
--data '{"type":"banana"}'

5. Observe that the backend returns 200 OK and creates the room:
HTTP/1.1 200 OK
{
"id": "882822",
"type": "banana"
}

Actual Behavior
The backend accepts the unsupported room type and creates a room with "type": "banana".

Expected Behavior
The backend should reject unsupported room types and return:
400 Bad Request
{
"error": "Invalid room type"
}

### Logs and Screenshots

Image

Image

Image

### Environment Details

_No response_

### Impact

High - Major feature is broken

### Code of Conduct

- [x] I have joined the [Discord server](https://discord.gg/hjUhu33uAn) and will post updates there
- [x] I have searched existing issues to avoid duplicates

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

Start by running the DebateAI backend and reproducing the issue with the provided POST /rooms curl request. Find the backend handler for POST /rooms and add validation so only public, private, and invite are accepted. Done means an unsupported type like banana returns 400 Bad Request with the stated error and no room is created.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
typescript
Ambito
api, backend
Tipo di issue
Bug
Difficoltà
2/5
Tempo stimato
1-3 ore
Stato di attività
Attiva
Chiarezza
Specificata chiaramente
Idoneità per principianti
74/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.