Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

`PATCH /editor/project/visibility` returns 200 with `null` and doesn't update when `projectId` is a slug

Aperta Adatta ai principianti
#4,348 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 3 giorni

@Prbhtsgh ci sta già lavorando.

Dal 8/10/2026.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
78/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
javascript, mongodb, node.js
Ambito
api, backend, database

Direzione di ricerca

Inizia in server/controllers/project.controller.js, in changeProjectVisibility intorno alle righe 446–487, e confronta la ricerca del progetto con la chiamata di aggiornamento. La segnalazione include una riproduzione che usa uno slug e un _id; verificali entrambi con l’endpoint. Il lavoro è concluso quando uno slug aggiorna il progetto di proprietà come previsto, oppure viene rifiutato con una risposta 4xx invece di restituire 200 con null.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Awaiting Maintainer Approval Bug
p5.js version

No response

What is your operating system?

Mac OS

Web browser and version

Google Chrome 153.0.8010.53 (Official Build) (arm64)

Actual Behavior

PATCH /editor/project/visibility looks up the project by either _id or slug, but then updates it by _id only. When a slug is sent as projectId, the ownership check passes, but the update matches no document. The visibility is not changed, and the server still responds 200 OK with null as the body.

In changeProjectVisibility (server/controllers/project.controller.js):

  • The lookup uses Project.findOne({ $or: [{ _id: projectId }, { slug: projectId }] }), which finds the project by slug.
  • The ownership check runs on that project and passes.
  • The update uses Project.findByIdAndUpdate(projectId, ...). With a slug, this searches for _id === "<slug>", matches nothing and returns null.
  • res.status(200).json(updatedProject) then sends null with status 200.

https://github.com/processing/p5.js-web-editor/blob/eab6aa4bfc542fcbff15e13303c98d3e97d25b4b/server/controllers/project.controller.js#L446-L487

The editor UI always sends the _id, so regular users don't hit this. It affects direct calls to the endpoint.

Checked related issues #3864 / #4291 / #3875 and PRs #3920 / #4305 / #3893. #3920 and #4305 change only client-side visibility state, and #3893 only restricts fields in updateProject. None of them change this lookup/update mismatch.

Expected Behavior

The update should apply to the same project that was found and ownership-checked, so sending a slug changes the visibility just like sending the _id. Alternatively, if slugs are not meant to be supported here, the endpoint should reject them with a 4xx error instead of responding 200 with null.

Steps to reproduce
Steps:

Reproduced on the latest develop branch, running locally with Docker.

  1. Log in, create a new sketch named visibility test, and save it. Its slug is visibility_test. You can confirm it in Mongo:
    db.projects.find({ name: 'visibility test' }, { slug: 1, visibility: 1 })
    In my case the visibility was Private.
  2. Toggle the sketch's visibility once from the toolbar, and copy the PATCH /editor/project/visibility request from DevTools (Network tab → Copy as cURL).
  3. Resend it with the body {"projectId":"visibility_test","visibility":"Public"}.
    • Response: 200 OK with the body null
    • In Mongo, the visibility is still Private (unchanged)
  4. Resend it with the body {"projectId":"<the sketch _id>","visibility":"Public"}.
    • Response: 200 OK with the full project JSON
    • In Mongo, the visibility is now Public

The only difference between steps 3 and 4 is sending the slug instead of the _id.

Possible fix

Update the project that was already found and checked, instead of looking it up again by the raw projectId:

const updatedProject = await Project.findByIdAndUpdate(
  project._id,
  { visibility: newVisibility },
  { new: true, runValidators: true }
)

I'd be happy to open a PR for this if the approach looks good.

Lingua principale
JavaScript
Stelle
1.7k
Fork
1.7k
Merge medio
3g 18h
PR unite (30g)
7

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di processing/p5.js-web-editor

Tutte le issue di processing/p5.js-web-editor

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.