fix: check destination calendar write access on event update (#24764)
update_event only verified write access on the event's source calendar. CalendarEventUpdateForm accepts a new calendar_id which the model layer applies unconditionally, so a user with write access to their own calendar could move (inject) an event into any other user's calendar. Mirror the destination check create_event already performs.
This commit is contained in:
@@ -301,6 +301,12 @@ async def update_event(
|
||||
|
||||
await _check_calendar_access(event.calendar_id, user, 'write')
|
||||
|
||||
# A new calendar_id in the form moves the event; require write access on the
|
||||
# destination too, mirroring create_event. Without this, write on the source
|
||||
# calendar alone is enough to inject an event into any other calendar.
|
||||
if form_data.calendar_id is not None and form_data.calendar_id != event.calendar_id:
|
||||
await _check_calendar_access(form_data.calendar_id, user, 'write')
|
||||
|
||||
updated = await CalendarEvents.update_event_by_id(event_id, form_data)
|
||||
if not updated:
|
||||
raise HTTPException(status_code=500, detail='Failed to update')
|
||||
|
||||
Reference in New Issue
Block a user