Details
-
Bug
-
Resolution: Fixed
-
High
-
3.3.2
Description
If one of the URL params is invalid (so string instead of int) we would receive a 500 exception. It would be a good practice to throw 404 in every case, like in the case of previewing content in the Back Office or similar when one param doesn't validate.
Steps to reproduce:
- Go to any of the following URLs:
/content/download/foo/bar
/content/download/123aaa/bar
Result:
500 exception is thrown.
Expected result:
404 exception is thrown.
Designs
Attachments
Issue Links
- relates to
-
IBX-356 Malicious request returns a valid response
- InputQ