• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

decentraland / social-service-ea / 35004170927
91%
main: 91%

Build:
Build:
LAST BUILD BRANCH: 1.13.12
DEFAULT BRANCH: main
Ran 15 Sep 2026 06:00PM UTC
Jobs 1
Files 210
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Sep 2026 05:45PM UTC coverage: 91.207% (-0.01%) from 91.218%
35004170927

push

github

web-flow
fix: stop returning private communities to unauthenticated callers (#488)

* fix: stop returning private communities to unauthenticated callers

getCommunityPublicInformation passes onlyPublic: true to the members-count CTE,
where it becomes `AND c.private = false` inside that CTE. The CTE only computes
counts and is LEFT JOINed, so the predicate filters nothing; the outer query is
just `WHERE c.id = $1 AND c.active = true`.

get-community-handler routes an unauthenticated request to this function, so
GET /v1/communities/<private id> answered 200 with the id, name, description,
owner address, Catalyst-resolved owner name and privacy: "private". The unmatched
join yields NULL for the count, so it read as a community with no members rather
than as anything unusual. /v2 shares the adapter method and behaved the same.

The predicate now sits in the query's own WHERE, so both versions return 404.

Only `private` is excluded. Unlisted communities stay reachable by id, which is
what unlisted means: hidden from discovery, not from someone holding the link.

The sibling list query puts the same predicate in its outer WHERE, which is what
made this a transcription slip rather than a decision.

* fix: gate the authenticated by-id read on private communities too

The first commit closed the unsigned path. A signed request takes a different
branch — getCommunity(id, { as }) — whose query filters only id and active and
uses the members join solely to compute role, so any wallet holding a private
community's id still received its name, description, owner, privacy, counts and
voice status with role: none.

Refusing only the anonymous half would have been worse than not fixing it, since
the register would have shown the finding closed.

Both versions now answer 404 unless the caller may see the community. The posts
and places reads already gate on `privacy === Private && role === None`, so this
follows the pattern rather than inventing one.

A pending invite counts as... (continued)

2599 of 2999 branches covered (86.66%)

Branch coverage included in aggregate %.

9 of 10 new or added lines in 1 file covered. (90.0%)

6249 of 6702 relevant lines covered (93.24%)

93.36 hits per line

Uncovered Changes

Lines Coverage ∆ File
1
94.62
-0.47% src/logic/community/communities.ts
Jobs
ID Job ID Ran Files Coverage
1 35004170927.1 15 Sep 2026 06:00PM UTC 420
92.08
GitHub Action Run
Source Files on build 35004170927
  • Tree
  • List 210
  • Changed 163
  • Source Changed 2
  • Coverage Changed 163
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #35004170927
  • 143e9aa3 on github
  • Prev Build on main (#34996768204)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc