Deleting/updating file attachments fails with 404 — frontend calls singular attachment/{type}:{id} but OCS route is plural attachments/{id}
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- javascript, php
Research direction
Start with src/services/attachment.js and compare deleteAttachment(), updateAttachment(), and restoreAttachment() with the OCS routes in appinfo/routes.php and AttachmentOcsController. Verify the request path and parameters against the confirmed working DELETE call, then exercise removing, updating, and restoring a file attachment to confirm all three operations succeed.
Written by the indexing model from the issue text.
Description
Describe the bug
Removing a file attachment (a file shared from Files, type: file) from a card via the sidebar (⋯ → Remove attachment) does nothing. The DELETE request returns HTTP 404 / OCS statuscode: 998 ("Invalid query"). The same mismatch affects updating and restoring attachments.
Steps to reproduce
Add a file to a card via "Share from Files" (creates a share_type 12 attachment).
Open the card, ⋯ on the attachment → Remove attachment.
Nothing happens; the Network tab shows a failed DELETE.
Actual request (fails):
DELETE /ocs/v2.php/apps/deck/api/v1.0/cards/52/attachment/file:198?boardId=7
→ 404, {"ocs":{"meta":{"status":"failure","statuscode":998,"message":"Invalid query, ..."}}}
Root cause
The frontend AttachmentApi builds the URL with singular attachment/ and a composite type🆔
// src/services/attachment.js (as shipped in js/deck-main.js)
async deleteAttachment(attachment, boardId) {
await axios({ method: 'DELETE',
url: this.ocsUrl(/cards/${attachment.cardId}/attachment/${attachment.type}:${attachment.id}),
params: { boardId: boardId ?? null } })
}
// updateAttachment() and restoreAttachment() use the same singular attachment/${type}:${id} scheme
But the OCS routes register delete/update/restore under plural attachments/{attachmentId} with type as a separate parameter:
// appinfo/routes.php (ocs)
['name' => 'attachment_ocs#delete', 'url' => '/api/v{apiVersion}/cards/{cardId}/attachments/{attachmentId}', 'verb' => 'DELETE'],
// AttachmentOcsController::delete(int $cardId, int $attachmentId, string $type = 'file', ?int $boardId = null)
So the singular path matches no OCS route → 998/404. (createAttachment POST /cards/{cardId}/attachment and getAll /cards/{cardId}/attachments both match fine — only delete/update/restore are inconsistent.)
Confirmed working call (proves the backend is fine, only the frontend URL is wrong):
DELETE /ocs/v2.php/apps/deck/api/v1.0/cards/52/attachments/198?type=file&boardId=7
→ 200 OK (share removed, source file kept)
Suggested fix
Align the frontend AttachmentApi delete/update/restore to /cards/${cardId}/attachments/${attachment.id} and pass type via params (matching the OCS controller). The shipped 1.18.2 JS bundle appears out of sync with the OCS routes.
Server configuration
Nextcloud: 34.0.1
Deck: 1.18.2 (files verified against the official signature.json — unmodified)
DB: MySQL · PHP 8.x · nginx (YunoHost)
Browser: Chrome 149
- Dominant language
- JavaScript
- Stars
- 1.4k
- Forks
- 358
- Avg merge
- 1d 9h
- Merged PRs (30d)
- 57
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from nextcloud/deck
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
nextcloud/deck#8334 · 1 comment ·
Maintainers usually reply within 1 day
-
Date picker should automatically open popupPossibly taken @theoholl claimed this 30 days ago. Open1. to develop enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
nextcloud/deck#8110 · 1 reaction ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
Similar issues
-
external-issue to-triage
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
LearningCircuit/local-deep-research#7067 ·
Maintainers usually reply within 1 day
-
automated issue report
Difficulty 1/5 Under an hour Newbie friendliness 65/100
lirantal/discoprint#32 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
Maintainers usually reply within 1 day