Storing a vCard accepts any well-formed XML document, and stores it as the user's vCard, even when its root element isn't a vCard element in the vcard-temp namespace. It's then returned as the user's vCard. Only a document that can't be parsed at all is rejected with a 400. A document that isn't a vCard should be rejected with a 400 too.
Steps to reproduce:
PUT /plugins/restapi/v1/users/{username}/vcard (for an existing user) with either body:
<vCard xmlns="wrong-namespace">
<FN>Someone</FN>
</vCard>
Expected: 400. Actual: 200, and the document is stored as the user's vCard.
Seen with REST API plugin 1.12.1-SNAPSHOT (main) on Openfire 5.1.2.
Storing a vCard accepts any well-formed XML document, and stores it as the user's vCard, even when its root element isn't a
vCardelement in thevcard-tempnamespace. It's then returned as the user's vCard. Only a document that can't be parsed at all is rejected with a 400. A document that isn't a vCard should be rejected with a 400 too.Steps to reproduce:
PUT /plugins/restapi/v1/users/{username}/vcard(for an existing user) with either body:<notavcard/>Expected: 400. Actual: 200, and the document is stored as the user's vCard.
Seen with REST API plugin 1.12.1-SNAPSHOT (
main) on Openfire 5.1.2.