Repository navigation
fix: return 403 join_rejected instead of 201 on rejected join - #16
Merged
Merged
Conversation
ThetaSinner
approved these changes
Aug 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #12.
POST /v1/joinreturned201 Createdwith{status: "rejected", reason}on a rejected join — and the session ID in that response was never persisted, so it was unusable anyway. Rejections now return403 Forbiddenwith the standard error shape:{ "error": { "code": "join_rejected", "message": "No eligible auth method in group" } }Breaking change for API consumers:
status === "rejected"on a 201 body. The bundled client now throwsJoiningErrorwithcode: "join_rejected"; CLI and UI flow updated accordingly.GET /statusandPOST /verifycan still returnstatus: "rejected"in a 200 body — a persisted session can be rejected later (e.g. admin block). A newStatusResponsetype covers this;JoinResponse.statusis narrowed to"ready" | "pending".Docs updated in JOINING_SERVICE_API.md (join rejection example/tables, /status response table, type appendix).