security: hide draft posts from public detail endpoint

Add post.draft? check to GET /api/volumen/posts/:slug so guessing a
draft slug returns 404 like the list endpoint already does.
This commit is contained in:
2026-06-25 22:06:49 +02:00
parent 1ca0212197
commit 263e794669
2 changed files with 7 additions and 1 deletions
+6
View File
@@ -103,4 +103,10 @@ class ServerTest < Minitest::Test
refute_includes body, "Draft"
assert_includes body, "<language>en</language>"
end
def test_draft_post_detail_is_not_found
get "/api/volumen/posts/draft"
assert_equal 404, last_response.status
assert_equal "not_found", JSON.parse(last_response.body)["error"]
end
end