mirror of
https://github.com/immich-app/immich.git
synced 2026-05-18 03:10:24 +03:00
fix(server): hide slug uniqueness constraint to prevent shared-link probe
Surfacing the Postgres unique-constraint name in the error response let any authenticated user brute-force whether a custom slug was already in use by another user's shared link, leaking the existence of other links.
This commit is contained in:
@@ -110,7 +110,7 @@ export class SharedLinkService extends BaseService {
|
|||||||
|
|
||||||
private handleError(error: unknown): never {
|
private handleError(error: unknown): never {
|
||||||
if ((error as PostgresError).constraint_name === 'shared_link_slug_uq') {
|
if ((error as PostgresError).constraint_name === 'shared_link_slug_uq') {
|
||||||
throw new BadRequestException('Shared link with this slug already exists');
|
throw new BadRequestException('Failed to save shared link');
|
||||||
}
|
}
|
||||||
throw error;
|
throw error;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user