From ff7d9d85fdfe1f639542461401d14a021e006e65 Mon Sep 17 00:00:00 2001 From: Jenny Danzmayr Date: Thu, 28 Dec 2023 15:27:43 +0100 Subject: [PATCH] fixed PUT on /positions/{position_id}/ API endpoint --- src/c3nav/mapdata/api/map.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/c3nav/mapdata/api/map.py b/src/c3nav/mapdata/api/map.py index 41f13743..db011cbc 100644 --- a/src/c3nav/mapdata/api/map.py +++ b/src/c3nav/mapdata/api/map.py @@ -291,10 +291,10 @@ class UpdatePositionSchema(BaseSchema): response={200: AnyPositionStatusSchema, **API404.dict(), **auth_permission_responses}) def set_position(request, position_id: AnyPositionID, update: UpdatePositionSchema): # todo: may an API key do this? - if not update.position_id.startswith('p:'): + if not isinstance(position_id, str) or not position_id.startswith('p:'): raise API404() try: - location = Position.objects.get(secret=update.position_id[2:]) + location = Position.objects.get(secret=position_id[2:]) except Position.DoesNotExist: raise API404() if location.owner != request.user: