From 20227403ce823a8e5950403c65250f2b9fb455ca Mon Sep 17 00:00:00 2001 From: Vishnu Narayanan Date: Thu, 9 Jul 2026 13:50:01 +0530 Subject: [PATCH] fix: return public contact inbox payload after update (#14946) # Pull Request Template ## Description This keeps the public inbox contact update response on the public contact inbox serializer shape after applying the contact identify update. ## Type of change - [x] Bug fix (non-breaking change which fixes an issue) - [ ] New feature (non-breaking change which adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to not work as expected) - [ ] This change requires a documentation update ## How Has This Been Tested? - `bundle exec rspec spec/controllers/public/api/v1/inbox/contacts_controller_spec.rb` ## Checklist: - [x] My code follows the style guidelines of this project - [x] I have performed a self-review of my own code - [ ] I have commented my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [ ] Any dependent changes have been merged and published in downstream modules Fixes [https://linear.app/chatwoot/issue/CW-6937](https://linear.app/chatwoot/issue/CW-6937) Fixes [https://linear.app/chatwoot/issue/CW-7464](https://linear.app/chatwoot/issue/CW-7464) Fixes [https://linear.app/chatwoot/issue/CW-7457](https://linear.app/chatwoot/issue/CW-7457) --- .../public/api/v1/inboxes/contacts_controller.rb | 3 ++- .../public/api/v1/inbox/contacts_controller_spec.rb | 12 ++++++++++++ 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/app/controllers/public/api/v1/inboxes/contacts_controller.rb b/app/controllers/public/api/v1/inboxes/contacts_controller.rb index 838b10951..764e02a72 100644 --- a/app/controllers/public/api/v1/inboxes/contacts_controller.rb +++ b/app/controllers/public/api/v1/inboxes/contacts_controller.rb @@ -18,7 +18,8 @@ class Public::Api::V1::Inboxes::ContactsController < Public::Api::V1::InboxesCon contact: @contact_inbox.contact, params: permitted_params.to_h.deep_symbolize_keys.except(:identifier) ) - render json: contact_identify_action.perform + contact_identify_action.perform + @contact_inbox.reload end private diff --git a/spec/controllers/public/api/v1/inbox/contacts_controller_spec.rb b/spec/controllers/public/api/v1/inbox/contacts_controller_spec.rb index 244d31c4d..5745b8e26 100644 --- a/spec/controllers/public/api/v1/inbox/contacts_controller_spec.rb +++ b/spec/controllers/public/api/v1/inbox/contacts_controller_spec.rb @@ -47,5 +47,17 @@ RSpec.describe 'Public Inbox Contacts API', type: :request do data = response.parsed_body expect(data['name']).to eq 'John Smith' end + + it 'does not expose internal contact columns' do + contact.update!(identifier: 'contact-identifier', custom_attributes: { tier: 'vip' }, additional_attributes: { company_name: 'Acme' }) + + patch "/public/api/v1/inboxes/#{api_channel.identifier}/contacts/#{contact_inbox.source_id}", + params: { name: 'John Smith' } + + expect(response).to have_http_status(:success) + data = response.parsed_body + expect(data.keys).to include('email', 'id', 'name', 'phone_number', 'pubsub_token', 'source_id') + expect(data.keys).not_to include('account_id', 'identifier', 'custom_attributes', 'additional_attributes', 'company_id') + end end end