Skip to content

fix: return 403 join_rejected instead of 201 on rejected join - #16

Merged
zippy merged 3 commits into
mainfrom
fix/join-rejected-403
Aug 14, 2026
Merged

zippy merged 3 commits into
mainfrom
fix/join-rejected-403

Conversation

@zippy

@zippy zippy commented Aug 13, 2026 •

Copy link
Copy Markdown
Member

Fixes #12.

POST /v1/join returned 201 Created with {status: "rejected", reason} on a rejected join — and the session ID in that response was never persisted, so it was unusable anyway. Rejections now return 403 Forbidden with the standard error shape:

{ "error": { "code": "join_rejected", "message": "No eligible auth method in group" } }

Breaking change for API consumers:

  • Handle join rejection as a non-2xx error instead of checking status === "rejected" on a 201 body. The bundled client now throws JoiningError with code: "join_rejected"; CLI and UI flow updated accordingly.
  • Unchanged: GET /status and POST /verify can still return status: "rejected" in a 200 body — a persisted session can be rejected later (e.g. admin block). A new StatusResponse type covers this; JoinResponse.status is narrowed to "ready" | "pending".

Docs updated in JOINING_SERVICE_API.md (join rejection example/tables, /status response table, type appendix).

@zippy
zippy requested a review from ThetaSinner August 14, 2026 12:22
@zippy
zippy merged commit ca1fef0 into main Aug 14, 2026
1 check passed
@zippy
zippy deleted the fix/join-rejected-403 branch August 14, 2026 12:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

201 status on rejected

2 participants