Skip to content

[HIGH] — Admin "suspend campaign" flow writes an AuditLog and resolves successfully, but never actually notifies the creator #6

Description

@ibrahimmosouf-png

Severity: High
Type: Bug
Scope: Admin, Notifications
Labels: bug, security, Official Campaign

Description

AdminService.suspendCampaign (src/admin/admin.service.ts, lines ~17–58) writes the campaign status change to the database and inserts an AuditLog entry, then calls this.notificationsService.sendCampaignSuspensionEmail(...). The implementation of sendCampaignSuspensionEmail (src/notifications/notifications.service.ts, lines ~159–173) has a TODO: replace with real mailer call marker and currently only emits a logger line — no email is queued, no in-app notification is created, and the recipient field is a synthetic creator-${creatorId}@platform.internal that cannot receive mail.

Result: an admin can confidently suspend a campaign, see the API return 200, and the creator receives nothing — meaning a campaign can be frozen with the creator unaware, blocking support requests and refunds.

Recommendation

  • Replace the stub with a real email template + Bull enqueue: render suspend-campaign-email.ts, push to QUEUE_EMAIL, and also create a Notification row for in-app delivery.
  • Add an integration test (AdminService.suspendCampaign + an injected mock NotificationsService) that asserts sendCampaignSuspensionEmail is invoked and the payload contains the real user.email (resolved through prisma.user.findUnique).
  • Surface the suspension asynchronously: have the controller return 202 if notification enqueuing fails so admins see the partial failure instead of a silent success.

Activity

  1. added
    bugSomething isn't working
    Official CampaignAudit finding under the Official Campaign
    securitySecurity vulnerability or hardening
    and removed
    Official CampaignAudit finding under the Official Campaign
    on Jun 18, 2026
  2. added
    GrantFox OSSIssue tracked in GrantFox OSS
    Maybe RewardedIssue may be eligible for a GrantFox reward
    Official CampaignAudit finding under the Official Campaign
    on Jun 18, 2026
  3. Just-Bamford commented on Jun 20, 2026

    @Just-Bamford
    Contributor

    Hi maintainer, I'd like to work on this issue. My approach is to replace the current notification stub with a production-ready notification flow by resolving the creator's actual email, rendering the suspension email template, enqueueing it through the email queue, and creating an in-app notification. I'll add integration tests to verify the correct recipient and notification payload, and ensure notification failures are surfaced back to the admin (e.g. via a 202 response) instead of appearing as a silent success.

  4. grantfox-oss commented on Jun 20, 2026

    @grantfox-oss

    🦊 GrantFox — @Just-Bamford has been assigned to this issue as part of the Official Campaign campaign!

    Next steps:

    1. Open a Pull Request referencing this issue (e.g., Closes #6)
    2. Your PR will be reviewed by the OrbitChainLabs maintainers

    Good luck! Track your progress on GrantFox.

  5. grantfox-oss commented on Jun 22, 2026

    @grantfox-oss

    🎉 This issue has been marked as completed on GrantFox as part of the Official Campaign campaign!

    @Just-Bamford's PR #35 was approved and merged by @Alqku.

    🏆 @Just-Bamford: You earned 35 FoxPoints for this contribution! Your current tier: Explorer (468 total points). Track your full progress on GrantFox.

    👏 Great work, @Just-Bamford! Keep contributing to OrbitChainLabs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial CampaignAudit finding under the Official CampaignbugSomething isn't workingsecuritySecurity vulnerability or hardening

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions