Files
open-webui/backend/open_webui
Classic298 ea058841c9 fix: check destination calendar write access on event update (#24764)
update_event only verified write access on the event's source calendar.
CalendarEventUpdateForm accepts a new calendar_id which the model layer
applies unconditionally, so a user with write access to their own calendar
could move (inject) an event into any other user's calendar. Mirror the
destination check create_event already performs.
2026-05-19 21:26:58 +04:00
..
2026-05-13 12:44:12 +09:00
2026-05-12 03:04:35 +09:00
2026-05-14 03:10:48 +09:00
2026-05-19 21:03:23 +04:00
2026-05-09 02:38:08 +09:00
2026-05-14 02:56:44 +09:00
2026-05-19 20:51:53 +04:00