diff options
author | Erik Michelson | 2021-03-29 23:00:34 +0200 |
---|---|---|
committer | Erik Michelson | 2021-03-29 23:00:34 +0200 |
commit | 124b06425214921c30a88e44a139b1cc8ca15b45 (patch) | |
tree | aa26e15cae2f48aa4651d54a2a21793e8ddd0a9d /lib/web | |
parent | 6531ea1a2144804677f6832646f18117b1e555a2 (diff) |
Check for existing notes on POST and dont override them
Previously one could override notes in FreeURL-mode by sending multiple POST requests to the /new/<alias> endpoint. This commit adds a check for an already existing note with the requested alias and returns a HTTP 409 Conflict error in case that happens.
Signed-off-by: Erik Michelson <opensource@erik.michelson.eu>
Diffstat (limited to 'lib/web')
-rw-r--r-- | lib/web/note/util.js | 15 |
1 files changed, 14 insertions, 1 deletions
diff --git a/lib/web/note/util.js b/lib/web/note/util.js index effeb41c..dbca5d8e 100644 --- a/lib/web/note/util.js +++ b/lib/web/note/util.js @@ -46,7 +46,7 @@ exports.checkViewPermission = function (req, note) { } } -exports.newNote = function (req, res, body) { +exports.newNote = async function (req, res, body) { let owner = null const noteId = req.params.noteId ? req.params.noteId : null if (req.isAuthenticated()) { @@ -60,6 +60,19 @@ exports.newNote = function (req, res, body) { } else { return req.method === 'POST' ? errors.errorForbidden(res) : errors.errorNotFound(res) } + try { + const count = await models.Note.count({ + where: { + alias: req.alias + } + }) + if (count > 0) { + return errors.errorConflict(res) + } + } catch (err) { + logger.error(err) + return errors.errorInternalError(res) + } } models.Note.create({ ownerId: owner, |