carrevue / carrevue/OpenSB

get_upload api is fucked

Open
#353 1 comment 0 reactions 1 assignee Claimed by @PF94 View on GitHub
bug
Dominant language
PHP
Stars
10
Forks
5
PR merge metrics
No merged PRs in 30d

Description

https://squarebracket.pw/api/v3/get_upload?id=9vbOjtCunZV

```json
{"id":"9vbOjtCunZV","title":"hi","description":"hi","author":{"username":"logan","displayname":"logan","color":"#3399cc","joined":1612069200,"connected":1724340655,"powerlevel":1,"flags":{"fulptube_account":false,"unverified":true,"featured":false,"profile_customization_enabled":false}},"uploaded":1612029600,"views":15,"file":"beaef5ec-78bb-4d8e-b618-6c90cc3eb93d.converted.mp4","type":0,"tags":[]}
```

well, this is embarrassing. there is so many things wrong with this:

1. in the case of pre-november 2024 video uploads, it returns a bullshit filename based off bunnycdn video streaming guids (due to a seldom-used db column). bunnycdn support was gutted in november 2024.
2. due to the userdata class now handling user flags, this exposes internal flags (fulptube account flag and unverified). there is no api to fetch a specific user however so this can't really be used as a way to, as an example, abuse verifications on fulptube/sb.
3. this upload's author is banned, it should return an error indicating so, yet it doesn't??? this also applies to taken down uploads.
4. while not shown in this example, tags are fucked. its json but gets encoded into a string???

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.