Skip to content

Validate typing conversation access#84

Merged
ralyodio merged 1 commit into
profullstack:masterfrom
phucnguyen1707:validate-typing-conversation-access
Jun 11, 2026
Merged

Validate typing conversation access#84
ralyodio merged 1 commit into
profullstack:masterfrom
phucnguyen1707:validate-typing-conversation-access

Conversation

@phucnguyen1707

Copy link
Copy Markdown
Contributor

Summary

  • require authenticated users to be active participants before typing start/stop broadcasts
  • return 403 for inaccessible conversations instead of emitting SSE events
  • add regression coverage for rejected and allowed typing start/stop requests

Fixes #83.

Tests

  • pnpm vitest run src/app/api/typing/route.test.js
  • pnpm vitest run src/app/api/messages/send/route.test.js src/app/api/typing/route.test.js

@ralyodio ralyodio merged commit fc64ff4 into profullstack:master Jun 11, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Typing API broadcasts to conversations without membership check

2 participants