fix: respect access_type in shared-chat file authorization branch (#24755)
has_access_to_file granted access whenever the file was attached to a shared chat the user could read, ignoring the requested access_type. A read-only shared-chat recipient therefore satisfied write and delete checks and could delete or mutate the chat owner's attached file. Gate the shared-chat branch on read access, matching the channels branch directly above it. Co-authored-by: oxsignal <oxsignal@users.noreply.github.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
oxsignal
Claude Opus 4.7
parent
5d104abd08
commit
d169f086da
@@ -66,7 +66,7 @@ async def has_access_to_file(
|
||||
|
||||
# Check if the file is associated with any chats the user has access to
|
||||
shared_chat_ids = await Chats.get_shared_chat_ids_by_file_id(file_id, db=db)
|
||||
if shared_chat_ids:
|
||||
if access_type == 'read' and shared_chat_ids:
|
||||
accessible_ids = await AccessGrants.get_accessible_resource_ids(
|
||||
user_id=user.id,
|
||||
resource_type='shared_chat',
|
||||
|
||||
Reference in New Issue
Block a user