Board ownership transfer to non-existent user
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 1.4k
- Forks
- 354
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 43
Description
How to use GitHub
- Please use the 👍 reaction to show that you are affected by the same issue.
- Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
- Subscribe to receive notifications on status change and new comments.
Describe the bug
The API endpoint responsible for transferring board ownership allows a user to specify a new owner via the newOwner parameter. However, the backend service does not validate whether the specified user actually exists in the system.
To Reproduce
Steps to reproduce the behavior:
- Create a new Deck board.
- Transfer ownership with
/apps/deck/boards/26/transferOwnerusing wrong new owner. - The requests is successful
Expected behavior
It returns an error Invalid request
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the handler for the Deck /apps/deck/boards/26/transferOwner endpoint and reproduce the request with an invalid newOwner. Read the surrounding ownership-transfer logic and its existing tests, if present; done means nonexistent users receive an Invalid request error while valid transfers continue to succeed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- api, backend
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100