fix: check destination calendar write access on event update (#24764)

update_event only verified write access on the event's source calendar.
CalendarEventUpdateForm accepts a new calendar_id which the model layer
applies unconditionally, so a user with write access to their own calendar
could move (inject) an event into any other user's calendar. Mirror the
destination check create_event already performs.
This commit is contained in:
Classic298
2026-05-19 21:26:58 +04:00
committed by GitHub
parent c48ac5163c
commit ea058841c9
+6
View File
@@ -301,6 +301,12 @@ async def update_event(
await _check_calendar_access(event.calendar_id, user, 'write')
# A new calendar_id in the form moves the event; require write access on the
# destination too, mirroring create_event. Without this, write on the source
# calendar alone is enough to inject an event into any other calendar.
if form_data.calendar_id is not None and form_data.calendar_id != event.calendar_id:
await _check_calendar_access(form_data.calendar_id, user, 'write')
updated = await CalendarEvents.update_event_by_id(event_id, form_data)
if not updated:
raise HTTPException(status_code=500, detail='Failed to update')