fix: align public_tools and public_notes sharing defaults with config (#27716)
The SharingPermissions model defaulted public_tools and public_notes to True while the config defaults (USER_PERMISSIONS_WORKSPACE_TOOLS_ALLOW_PUBLIC_SHARING and USER_PERMISSIONS_NOTES_ALLOW_PUBLIC_SHARING) are both False. On an instance whose stored user.permissions config predates these keys, GET /api/v1/users/default/permissions fills the gap from the model and reports both as enabled, while has_permission fills it from DEFAULT_USER_PERMISSIONS and denies. Saving any unrelated permission then persists the model's True, granting public tool and note sharing the admin never enabled.
This commit is contained in:
@@ -227,11 +227,11 @@ class SharingPermissions(BaseModel):
|
||||
prompts: bool = False
|
||||
public_prompts: bool = False
|
||||
tools: bool = False
|
||||
public_tools: bool = True
|
||||
public_tools: bool = False
|
||||
skills: bool = False
|
||||
public_skills: bool = False
|
||||
notes: bool = False
|
||||
public_notes: bool = True
|
||||
public_notes: bool = False
|
||||
folders: bool = False
|
||||
public_chats: bool = False
|
||||
public_calendars: bool = False
|
||||
|
||||
Reference in New Issue
Block a user