`PATCH /editor/project/visibility` returns 200 with `null` and doesn't update when `projectId` is a slug
I maintainer di solito rispondono entro 3 giorni
@Prbhtsgh ci sta già lavorando.
Dal 8/10/2026.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 78/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- javascript, mongodb, node.js
Direzione di ricerca
Inizia in server/controllers/project.controller.js, in changeProjectVisibility intorno alle righe 446–487, e confronta la ricerca del progetto con la chiamata di aggiornamento. La segnalazione include una riproduzione che usa uno slug e un _id; verificali entrambi con l’endpoint. Il lavoro è concluso quando uno slug aggiorna il progetto di proprietà come previsto, oppure viene rifiutato con una risposta 4xx invece di restituire 200 con null.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
p5.js version
No response
What is your operating system?
Mac OS
Web browser and version
Google Chrome 153.0.8010.53 (Official Build) (arm64)
Actual Behavior
PATCH /editor/project/visibility looks up the project by either _id or slug, but then updates it by _id only. When a slug is sent as projectId, the ownership check passes, but the update matches no document. The visibility is not changed, and the server still responds 200 OK with null as the body.
In changeProjectVisibility (server/controllers/project.controller.js):
- The lookup uses
Project.findOne({ $or: [{ _id: projectId }, { slug: projectId }] }), which finds the project by slug. - The ownership check runs on that project and passes.
- The update uses
Project.findByIdAndUpdate(projectId, ...). With a slug, this searches for_id === "<slug>", matches nothing and returnsnull. res.status(200).json(updatedProject)then sendsnullwith status 200.
The editor UI always sends the _id, so regular users don't hit this. It affects direct calls to the endpoint.
Checked related issues #3864 / #4291 / #3875 and PRs #3920 / #4305 / #3893. #3920 and #4305 change only client-side visibility state, and #3893 only restricts fields in updateProject. None of them change this lookup/update mismatch.
Expected Behavior
The update should apply to the same project that was found and ownership-checked, so sending a slug changes the visibility just like sending the _id. Alternatively, if slugs are not meant to be supported here, the endpoint should reject them with a 4xx error instead of responding 200 with null.
Steps to reproduce
Steps:
Reproduced on the latest develop branch, running locally with Docker.
- Log in, create a new sketch named
visibility test, and save it. Its slug isvisibility_test. You can confirm it in Mongo:
db.projects.find({ name: 'visibility test' }, { slug: 1, visibility: 1 })
In my case the visibility wasPrivate. - Toggle the sketch's visibility once from the toolbar, and copy the
PATCH /editor/project/visibilityrequest from DevTools (Network tab → Copy as cURL). - Resend it with the body
{"projectId":"visibility_test","visibility":"Public"}.- Response:
200 OKwith the bodynull - In Mongo, the visibility is still
Private(unchanged)
- Response:
- Resend it with the body
{"projectId":"<the sketch _id>","visibility":"Public"}.- Response:
200 OKwith the full project JSON - In Mongo, the visibility is now
Public
- Response:
The only difference between steps 3 and 4 is sending the slug instead of the _id.
Possible fix
Update the project that was already found and checked, instead of looking it up again by the raw projectId:
const updatedProject = await Project.findByIdAndUpdate(
project._id,
{ visibility: newVisibility },
{ new: true, runValidators: true }
)
I'd be happy to open a PR for this if the approach looks good.
- Lingua principale
- JavaScript
- Stelle
- 1.7k
- Fork
- 1.7k
- Merge medio
- 3g 18h
- PR unite (30g)
- 7
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di processing/p5.js-web-editor
-
Fix: example.js stores defaultHTML function reference instead of calling it, causing examples to display raw JavaScript source in previewForse già presa @syedbarkath980 l’ha presa 5 giorni fa. ApertaAwaiting Maintainer Approval Bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
processing/p5.js-web-editor#4344 · 1 commento ·
I maintainer di solito rispondono entro 3 giorni
-
signup form gets stuck when signup request fails due to network errorForse già presa @PS01K l’ha presa 34 giorni fa. ApertaAwaiting Maintainer Approval Bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
processing/p5.js-web-editor#4285 · 3 commenti ·
I maintainer di solito rispondono entro 3 giorni
-
saveProject throws an error when a network request failsForse già presa @dyk1454683243-sudo l’ha presa 6 giorni fa. ApertaBug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
processing/p5.js-web-editor#4276 · 3 commenti · 1 assegnatario ·
I maintainer di solito rispondono entro 3 giorni
-
Awaiting Maintainer Approval Enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
processing/p5.js-web-editor#4270 · 1 commento ·
I maintainer di solito rispondono entro 3 giorni
-
"Add Sketch" option visible to guest users on other users collectionsForse già presa @Riddh1ma l’ha presa 122 giorni fa. ApertaBug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
processing/p5.js-web-editor#4148 ·
I maintainer di solito rispondono entro 3 giorni
Tutte le issue di processing/p5.js-web-editor
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
`yarn vitest:update` (documented) throws locally; local Cypress scripts target an unserved portAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
rescript-lang/rescript-lang.org#1415 ·
I maintainer di solito rispondono entro 2 giorni
-
[Bug]: agent capture drops long Unicode text as punctuationForse già presa @ktz03 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
volcengine/OpenViking#5801 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
Deepak3699/Ai_Mentor#244 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
nextcloud/collectives#2843 ·
I maintainer di solito rispondono entro 1 giorno