Fix guest search security (#10021)

* Fix guest search security

Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>

* Fix formatting

Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>

---------

Signed-off-by: Denis Bykhov <bykhov.denis@gmail.com>
This commit is contained in:
Denis Bykhov
2025-10-04 07:05:50 +07:00
committed by GitHub
parent eed5a13363
commit 35d2a18329
+11 -8
View File
@@ -509,14 +509,17 @@ export class SpaceSecurityMiddleware extends BaseMiddleware implements Middlewar
await this.next?.handleBroadcast(ctx)
}
private getAllAllowedSpaces (account: Account, isData: boolean, showArchived: boolean): Ref<Space>[] {
private getAllAllowedSpaces (
account: Account,
isData: boolean,
showArchived: boolean,
forSearch: boolean = false
): Ref<Space>[] {
const userSpaces = this.allowedSpaces[account.uuid] ?? []
const res = [
...Array.from(userSpaces),
account.uuid as unknown as Ref<Space>,
...this.systemSpaces,
...this.mainSpaces
]
let res = [...Array.from(userSpaces), account.uuid as unknown as Ref<Space>, ...this.mainSpaces]
if (!forSearch || ![AccountRole.Guest, AccountRole.ReadOnlyGuest].includes(account.role)) {
res = [...res, ...this.systemSpaces]
}
const ignorePublicSpaces = isData || account.role === AccountRole.ReadOnlyGuest
const unfilteredRes = ignorePublicSpaces ? res : [...res, ...this.publicSpaces]
if (showArchived) {
@@ -690,7 +693,7 @@ export class SpaceSecurityMiddleware extends BaseMiddleware implements Middlewar
const newQuery = { ...query }
const account = ctx.contextData.account
if (!isSystem(account, ctx)) {
const allSpaces = this.getAllAllowedSpaces(account, true, false)
const allSpaces = this.getAllAllowedSpaces(account, true, false, true)
if (query.classes !== undefined) {
const res = new Set<Ref<Space>>()
const passedDomains = new Set<string>()