Procházet zdrojové kódy

Sanitise error messages when user doesn't have permission to invite

Erik Johnston před 5 roky
rodič
revize
52e6e815be
1 změnil soubory, kde provedl 2 přidání a 5 odebrání
  1. 2 5
      synapse/event_auth.py

+ 2 - 5
synapse/event_auth.py

@@ -155,10 +155,7 @@ def check(event, auth_events, do_sig_check=True, do_size_check=True):
 
         if user_level < invite_level:
             raise AuthError(
-                403, (
-                    "You cannot issue a third party invite for %s." %
-                    (event.content.get("display_name", "<Unknown>"),)
-                )
+                403, "You don't have permission to invite users",
             )
         else:
             logger.debug("Allowing! %s", event)
@@ -305,7 +302,7 @@ def _is_membership_change_allowed(event, auth_events):
 
             if user_level < invite_level:
                 raise AuthError(
-                    403, "You cannot invite user %s." % target_user_id
+                    403, "You don't have permission to invite users",
                 )
     elif Membership.JOIN == membership:
         # Joins are valid iff caller == target and they were: