Uploaded image for project: 'MusicBrainz Server'
  1. MusicBrainz Server
  2. MBS-13058

Return 404 for /applications/revoke-access if token does not exist

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Normal Normal
    • 2023-08-07
    • None
    • User interface
    • None

      There's nothing blocking me from entering whatever integers in the URL for something like https://musicbrainz.org/account/applications/revoke-access/19043349434/32343 - including ending up on someone else's application (edit: actually, the IDs here are just application and scope so there's nothing personalized about them). This will fail when I actually try to submit it, but it should probably just give me a 404 instead.

            reosarevok Nicolás Tamargo
            reosarevok Nicolás Tamargo
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:

                Version Package
                2023-08-07