Adding a username that doesn't exist to a group returns 201, and adds {username}@{xmpp domain} to the group's members. Getting the groups of that username returns 404, so the two endpoints are inconsistent. Groups can legitimately contain JIDs of remote users (#40), but a value without @ can only mean a local user, so it could be checked for existence and rejected with a 404.
Steps to reproduce:
Either of:
POST /plugins/restapi/v1/users/nonexistent/groups/{groupName} (for an existing group)
POST /plugins/restapi/v1/users/nonexistent/groups with body:
<groups>
<groupname>{groupName}</groupname>
</groups>
Expected: 404. Actual: 201, and nonexistent@{xmpp domain} is a member of the group.
Seen with REST API plugin 1.12.1-SNAPSHOT (main) on Openfire 5.1.2.
Adding a username that doesn't exist to a group returns 201, and adds
{username}@{xmpp domain}to the group's members. Getting the groups of that username returns 404, so the two endpoints are inconsistent. Groups can legitimately contain JIDs of remote users (#40), but a value without@can only mean a local user, so it could be checked for existence and rejected with a 404.Steps to reproduce:
Either of:
POST /plugins/restapi/v1/users/nonexistent/groups/{groupName}(for an existing group)POST /plugins/restapi/v1/users/nonexistent/groupswith body:Expected: 404. Actual: 201, and
nonexistent@{xmpp domain}is a member of the group.Seen with REST API plugin 1.12.1-SNAPSHOT (
main) on Openfire 5.1.2.