diff --git a/sachet/server/files/views.py b/sachet/server/files/views.py index 6a44bb3..e898e8b 100644 --- a/sachet/server/files/views.py +++ b/sachet/server/files/views.py @@ -27,6 +27,13 @@ class FilesMetadataAPI(ModelAPI): @auth_required(required_permissions=(Permissions.DELETE,)) def delete(self, share_id, auth_user=None): + try: + uuid.UUID(share_id) + except ValueError: + return jsonify(dict( + status="fail", + message=f"Invalid ID: '{share_id}'." + )) share = Share.query.filter_by(share_id=share_id).first() return super().delete(share)