nextcloud / nextcloud/deck

Reorder API endpoint does not follow REST best practises - target stack in reorder endpoint path

Open
#8,255 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

1. to develop bug
Dominant language
JavaScript
Stars
1.4k
Forks
354
Avg merge
1d 10h
Merged PRs (30d)
43

Description

How to use GitHub
  • Please use the 👍 reaction to show that you are affected by the same issue.
  • Please don't comment if you have no relevant information to add. It's just extra noise for everyone subscribed to this issue.
  • Subscribe to receive notifications on status change and new comments.

Describe the bug
When calling the card reorder endpoint, the stack ID in the path is used as target stack, while the documented body parameter is ignored.

Following REST principles the path would identify the resource while the body contains the parameters. So correct would be to put the current stack in the path and the target stack in the body.

To Reproduce
Steps to reproduce the behavior:

  1. Put the current stackId in the path variable and the target stackId in the body - nothing happens.
  2. Put the target stackId in the path - the card is moved

May also be connected to #6830

Expected behavior
Follow the 4th principle of REST: Consistency. The path variable is actually used as identifier in other requests, just not in the reorder endpoint.

Screenshots

Client details:

Server details

Operating system:

Web server:

Database:

PHP version:

Nextcloud version: (see Nextcloud admin page)

Where did you install Nextcloud from:

Signing status:

Login as admin user into your Nextcloud and access
http://example.com/index.php/settings/integrity/failed
paste the results here.

List of activated apps:

If you have access to your command line run e.g.:
sudo -u www-data php occ app:list
from within your Nextcloud installation folder

Nextcloud configuration:

If you have access to your command line run e.g.:
sudo -u www-data php occ config:list system
from within your Nextcloud installation folder

or

Insert your config.php content here
Make sure to remove all sensitive content such as passwords. (e.g. database password, passwordsalt, secret, smtp password, …)

Are you using an external user-backend, if yes which one: LDAP/ActiveDirectory/Webdav/...

Logs
Nextcloud log (data/nextcloud.log)
Insert your Nextcloud log here
Browser log
Insert your browser log here, this could for example include:

a) The javascript console log
b) The network log
c) ...

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the card reorder endpoint from its route and reproduce both request forms described in the issue. Trace how the path stack ID and documented body parameter are read, then verify the endpoint consistently treats the path as the current stack and the body as the target stack without breaking existing requests.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
api, backend-api-design
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.