Read RFC 9457 errors for a refused capture, not detail, or the person stops being told which field is wrong #1
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-chromium#1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Postulo's API answers a refusal with an RFC 9457 problem document since
postulo/postulo#296.
src/lib/api.jsreads the old shape, and one line of it quietlystops working.
refusalForat:90-92does:The second branch was the useful one: a 422 carried the list of refused fields, each with
its
locandmsg, andproblemturned them into "title: Field required".detailisa string in every refusal now, so that branch is dead and the person sees the core's
one-line summary — "Refused: title. See
errorsfor what is wrong with each." — insteadof what is wrong with each.
Nothing breaks. It just says less, which is worse in the place it matters most: somebody
capturing a posting that will not go in, who needs to know which field to correct.
Fix
Read
errors, which holds exactly whatdetailused to:Keep the
detailfallback: it is what an older Postulo sends, and an extension is updatedon a different day from the instance it talks to.
While there
403readsbody.detailfor the scope. That still works, andbody.scopenow carriesthe scope on its own — worth using rather than showing a sentence built for a developer.
429throws a generic tooMany.body.retry_after(and theRetry-Afterheader) sayhow long, which is the one thing the person wants to know.
Problemcomponent.postulo-firefox builds from this repository's source, so it takes the fix with the next
build.