mirror of
https://github.com/wanderer-industries/wanderer
synced 2026-10-08 20:51:26 +00:00
Two polish follow-ups on the /api/v1 authz branch:
1. Map duplication never actually copied signatures. get_all_map_signatures
called `MapSystemSignature.by_system_id_all(%{system_id: id})`, but the
code interface is defined with `args: [:system_id]` and every other call
site passes the id positionally. The map form raised
Ash.Error.Query.InvalidArgument on :system_id, which the old
`{:error, _} -> []` swallow silently turned into "no signatures", so
duplication reported success while copying none. Fixed the call to pass
the id positionally; the surrounding reduce now propagates a read failure
as {:error, {:signature_read_failed, _}} and rolls back rather than
returning an incomplete duplicate as success.
2. Added a custom-endpoint test asserting the systems_and_connections IDOR
guard is not loosened into case-folding: an upper-cased own-map id must
still 404, confirming to_string/1 normalization guards rather than matches
loosely.
Verified: all /api/v1 authz suites, map_scoped units, and the four map
duplication suites pass (157/0 at seed 0).