AOSSIE-Org / AOSSIE-Org/Resonate-Backend

Missing room existence validation in join-room allows tokens for non-existent rooms

Open
#154 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
43
Forks
120
PR merge metrics
No merged PRs in 30d

Description

**Problem**
The join-room function generates LiveKit access tokens without verifying the room exists in Appwrite. Users can receive valid tokens for non-existent or deleted rooms, causing poor UX, wasted resources, and potential security issues.

**Affected Code**
functions/join-room/src/main.js

The function accepts roomName and uid, generates a token immediately, and returns success without checking room existence.

**Proposed Fix**
Add room existence validation by querying ROOMS_COLLECTION_ID before token generation. Return 404 if room doesn't exist.

**Acceptance Criteria**
- Room existence verified before token generation
- Returns 404 with clear error message if room not found
- Existing functionality unchanged for valid rooms
- Error handling follows existing patterns

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.