Repository navigation
fix: answer unknown guest tokens with 403 instead of an error page - #97
Merged
Merged
Conversation
TicketService.findByGuestToken throws EntityNotFoundException, which no
handler mapped. The container forwarded it to /error, which host security
refuses for anonymous callers, so guests got 401 with no body (500 on hosts
without that security). The widget and guest-access token endpoints now
return 403 {"error":"Invalid guest access token"}, matching the NestJS
reference's GuestAccessGuard.
This was referenced Oct 5, 2026
# Conflicts: # src/main/java/dev/escalated/controllers/widget/GuestAccessController.java # src/main/java/dev/escalated/controllers/widget/WidgetController.java
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
TicketService.findByGuestTokenthrowsEntityNotFoundExceptionfor a token that matches no ticket. Nothing mapped that exception to a status. The servlet container forwarded it to/error, and the host's own security refuses/errorfor an anonymous caller. In practice a guest with an unknown token got 401 with an empty body, not the 500 we expected. A host without that security would show a 500 error page.Fix
The six guest-token endpoints now catch the lookup failure and return
403 {"error":"Invalid guest access token"}:GET /tickets/{token},GET /tickets/{token}/replies,POST /tickets/{token}/repliesGET /tickets/{token},GET /tickets/{token}/replies,POST /tickets/{token}/repliesThis follows the repo's convention. There is no
@ControllerAdvice; controllers catchEntityNotFoundExceptionthemselves (asSkillControllerdoes) and returnMap.of("error", ...)bodies (asAgentTicketControllerdoes).Why 403 rather than 404: the NestJS reference's
GuestAccessGuardthrowsForbiddenException('Invalid guest access token')for an unknown token, so this matches it. The dotnet and phoenix ports return 404 for the same case, so the ports are not consistent with each other.Tests
GuestTokenNotFoundTestboots the host on a random port and sends real HTTP requests, with no service stubs and no MockMvc.expected: 403 but was: 401.Results
./gradlew test(H2): 370 tests, 0 failures, 0 errors, 9 skipped (the skips were already there)./gradlew checkstyleMain checkstyleTest: BUILD SUCCESSFUL, with no warnings in the touched filesSeen, not fixed here
GET /escalated/api/guest/tickets/{token}with a valid token serialises theTicketentity graph cyclically. The response was about 45 KB of repeated nesting (activities-> ticket -> ...). That is why the positive control asserts the status only. It needs a separate fix: a DTO or@JsonIgnoreon the back-references.Related: #96, whose wrong-token test can then use the real endpoint instead of a stub.