CSCfi / CSCfi/rems

Inconsistent handle-command validation messages

Open
#3,134 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Clojure
Stars
66
Forks
28
Avg merge
7d 4h
Merged PRs (30d)
2

Description

Command handlers can return misleading error messages when user does not have permission.

E.g. with `:member` role, API call to command `:application.command/submit` can return "licenses not accepted" or form validation error before forbidden error. This leaks information from the application to user who does not have permission. It is also weird logic that command handler is executed before user permission.

> Test what the UX / behavior of API is when an applicant creates a draft, then a member tries to submit it. Also test what happens when unrelated user tries to submit it it. Does it make sense?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.