Files
open-webui/backend/open_webui/routers
Classic298 ea058841c9 fix: check destination calendar write access on event update (#24764)
update_event only verified write access on the event's source calendar.
CalendarEventUpdateForm accepts a new calendar_id which the model layer
applies unconditionally, so a user with write access to their own calendar
could move (inject) an event into any other user's calendar. Mirror the
destination check create_event already performs.
2026-05-19 21:26:58 +04:00
..
2026-05-19 21:24:58 +04:00
2026-05-14 13:10:37 +09:00
2026-05-19 20:44:38 +04:00
2026-05-14 02:25:16 +09:00
2026-05-14 13:12:59 +09:00
2026-05-14 02:40:20 +09:00
2026-05-13 22:37:53 +09:00
2026-05-14 13:19:00 +09:00
2026-05-14 13:12:59 +09:00