diff --git a/server/routes/share-api.ts b/server/routes/share-api.ts index 33c32767..d10b68bd 100644 --- a/server/routes/share-api.ts +++ b/server/routes/share-api.ts @@ -85,7 +85,7 @@ const app = new Hono() const { share } = resolved if (share.kind !== 'landing') return c.json({ error: 'Share not found or revoked' }, 404) - if (!verifyPassword(share, password)) return c.json({ error: 'Invalid password' }, 401) + if (!verifyPassword(share, password)) return c.json({ error: 'Invalid password' }, 403) const now = new Date() const oneDayMs = 24 * 60 * 60 * 1000 diff --git a/server/routes/share-public.integration.test.ts b/server/routes/share-public.integration.test.ts index a60c2e31..be9b66f4 100644 --- a/server/routes/share-public.integration.test.ts +++ b/server/routes/share-public.integration.test.ts @@ -214,7 +214,7 @@ describe('POST /s/:token/verify', () => { expect(cookieHeader).toContain('HttpOnly') }) - it('returns 401 on wrong password', async () => { + it('returns 403 on wrong password', async () => { const { app, db } = await createTestApp() await authedHeaders(app) await insertStorage(db) @@ -234,7 +234,7 @@ describe('POST /s/:token/verify', () => { headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ password: 'wrongpassword' }), }) - expect(res.status).toBe(401) + expect(res.status).toBe(403) }) }) diff --git a/src/components/share/password-prompt.tsx b/src/components/share/password-prompt.tsx index c81e6d24..cf8fbbe0 100644 --- a/src/components/share/password-prompt.tsx +++ b/src/components/share/password-prompt.tsx @@ -25,7 +25,7 @@ export function PasswordPrompt({ token, fileName, onUnlocked }: PasswordPromptPr await verifySharePassword(token, password) onUnlocked() } catch (err) { - if (err instanceof ApiError && err.status === 401) { + if (err instanceof ApiError && err.status === 403) { setError(t('share.passwordWrong')) } else { setError(t('share.loadError')) diff --git a/src/lib/api.test.ts b/src/lib/api.test.ts index b4608a2c..7895740e 100644 --- a/src/lib/api.test.ts +++ b/src/lib/api.test.ts @@ -1152,8 +1152,8 @@ describe('api', () => { expect(JSON.parse(init.body as string)).toEqual({ password: 'secret' }) }) - it('throws ApiError on 401 (wrong password)', async () => { - vi.mocked(fetch).mockResolvedValueOnce(makeResponse({ error: 'Invalid password' }, false, 401)) + it('throws ApiError on 403 (wrong password)', async () => { + vi.mocked(fetch).mockResolvedValueOnce(makeResponse({ error: 'Invalid password' }, false, 403)) await expect(verifySharePassword('tok123', 'wrong')).rejects.toThrow('Invalid password') })