diff --git a/app/controllers/topics_controller.rb b/app/controllers/topics_controller.rb index b5d910a8259..aca86dd57c0 100644 --- a/app/controllers/topics_controller.rb +++ b/app/controllers/topics_controller.rb @@ -51,6 +51,10 @@ class TopicsController < ApplicationController end def show + if params[:id].is_a?(Array) + raise Discourse::InvalidParameters.new("Show only accepts a single ID") + end + flash["referer"] ||= request.referer[0..255] if request.referer # TODO: We'd like to migrate the wordpress feed to another url. This keeps up backwards diff --git a/spec/requests/topics_controller_spec.rb b/spec/requests/topics_controller_spec.rb index 66af5a01982..94eed15ed3b 100644 --- a/spec/requests/topics_controller_spec.rb +++ b/spec/requests/topics_controller_spec.rb @@ -2322,6 +2322,12 @@ RSpec.describe TopicsController do expect(response).to redirect_to(topic.relative_url) end + it "does not raise an unhandled exception when receiving an array of IDs" do + get "/t/#{topic.id}/summary?id[]=a,b" + + expect(response.status).to eq(400) + end + it "keeps the post_number parameter around when redirecting" do get "/t/#{topic.slug}", params: { post_number: 42 } expect(response).to redirect_to(topic.relative_url + "/42")