Skip to content

Allow only authorised roles to access UpdateClubView endpoint #234

@PranshuNayak

Description

@PranshuNayak

Issue summary

When an authenticated yet unauthorized user (not a core member nor a staff user) tries to access the UpdateClubView endpoint with a club id that does not exist in the database, API returns HTTP404 instead of HTTP403.

Steps to reproduce

Modify the permissions to access the endpoint

Versions

- Python:
- Django:
- Node:
- React:
- Browser:

Terms

  • I have confirmed that this issue can be reproduced as described on a fresh gymkhana project.

Any other relevant information?

issue

Metadata

Metadata

Assignees

No one assigned

    Labels

    APIto label task requiring changes in APIbugSomething isn't workinggood first issueGood for newcomers

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions