From ea058841c91dc38b6dd6d81463429a53282823cb Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Tue, 19 May 2026 19:26:58 +0200 Subject: [PATCH] fix: check destination calendar write access on event update (#24764) update_event only verified write access on the event's source calendar. CalendarEventUpdateForm accepts a new calendar_id which the model layer applies unconditionally, so a user with write access to their own calendar could move (inject) an event into any other user's calendar. Mirror the destination check create_event already performs. --- backend/open_webui/routers/calendar.py | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/backend/open_webui/routers/calendar.py b/backend/open_webui/routers/calendar.py index 6c567aa3a8..5d397ea868 100644 --- a/backend/open_webui/routers/calendar.py +++ b/backend/open_webui/routers/calendar.py @@ -301,6 +301,12 @@ async def update_event( await _check_calendar_access(event.calendar_id, user, 'write') + # A new calendar_id in the form moves the event; require write access on the + # destination too, mirroring create_event. Without this, write on the source + # calendar alone is enough to inject an event into any other calendar. + if form_data.calendar_id is not None and form_data.calendar_id != event.calendar_id: + await _check_calendar_access(form_data.calendar_id, user, 'write') + updated = await CalendarEvents.update_event_by_id(event_id, form_data) if not updated: raise HTTPException(status_code=500, detail='Failed to update')