fix: add missing read-access check on channel members endpoint (#23625)

The GET /channels/{id}/members endpoint checked membership for group/dm channels but had no access gate for standard channels, allowing any authenticated user with channels permission to enumerate members of private standard channels by UUID.
This commit is contained in:
Classic298
2026-04-12 12:41:51 -05:00
committed by GitHub
parent 15f9a8f3f1
commit b618d84065
+3
View File
@@ -467,6 +467,9 @@ async def get_channel_members_by_id(
if channel.type in ['group', 'dm']:
if not Channels.is_user_channel_member(channel.id, user.id, db=db):
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
else:
if user.role != 'admin' and not channel_has_access(user.id, channel, permission='read', db=db):
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
if channel.type == 'dm':
user_ids = [member.user_id for member in Channels.get_members_by_channel_id(channel.id, db=db)]