AOSSIE-Org / AOSSIE-Org/Resonate-Backend

Missing room existence validation in join-room allows tokens for non-existent rooms

未关闭
#154 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
JavaScript
星标
43
派生
120
PR 合并指标
30 天内没有已合并 PR

描述

**Problem**
The join-room function generates LiveKit access tokens without verifying the room exists in Appwrite. Users can receive valid tokens for non-existent or deleted rooms, causing poor UX, wasted resources, and potential security issues.

**Affected Code**
functions/join-room/src/main.js

The function accepts roomName and uid, generates a token immediately, and returns success without checking room existence.

**Proposed Fix**
Add room existence validation by querying ROOMS_COLLECTION_ID before token generation. Return 404 if room doesn't exist.

**Acceptance Criteria**
- Room existence verified before token generation
- Returns 404 with clear error message if room not found
- Existing functionality unchanged for valid rooms
- Error handling follows existing patterns

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。