Enforce roles on admin endpoints and return real status codes
- users, SMTP and batch-lock endpoints are owner/admin only - engines answer 400/403/404/409/500 instead of 200 with an error body; database errors no longer leak to the client
This commit is contained in:
@@ -10,11 +10,13 @@ $action = $data['action'] ?? '';
|
||||
$data['items'] = json_decode($data['items'] ?? '[]', true) ?: [];
|
||||
|
||||
if (!in_array($action, ['create', 'update'], true)) {
|
||||
http_response_code(400);
|
||||
$answer['message'] = 'Unknown action';
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
if (empty($data['items'])) {
|
||||
http_response_code(400);
|
||||
$answer['message'] = 'At least one item is required';
|
||||
exit(json_encode($answer));
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user