The API documents that adding a user to a group that doesn't exist creates that group. Instead, it returns a 500 and creates nothing. UserServiceController creates the group from a GroupEntity without members or admins, and GroupController.createGroup requires those lists, so it throws a NullPointerException.
Steps to reproduce:
Either of:
POST /plugins/restapi/v1/users/{username}/groups/{groupName} (for an existing user and a group that doesn't exist)
POST /plugins/restapi/v1/users/{username}/groups (for an existing user) with body:
<groups>
<groupname>nonexistent</groupname>
</groups>
Expected: 201, with the group created and the user a member of it. Actual: 500.
Seen with REST API plugin 1.12.1-SNAPSHOT (main) on Openfire 5.1.2.
The API documents that adding a user to a group that doesn't exist creates that group. Instead, it returns a 500 and creates nothing.
UserServiceControllercreates the group from aGroupEntitywithout members or admins, andGroupController.createGrouprequires those lists, so it throws aNullPointerException.Steps to reproduce:
Either of:
POST /plugins/restapi/v1/users/{username}/groups/{groupName}(for an existing user and a group that doesn't exist)POST /plugins/restapi/v1/users/{username}/groups(for an existing user) with body:Expected: 201, with the group created and the user a member of it. Actual: 500.
Seen with REST API plugin 1.12.1-SNAPSHOT (
main) on Openfire 5.1.2.