EQMS-1614 Add separate check method for inverted permissions (#9623)

Signed-off-by: Alexander Onnikov <Alexander.Onnikov@xored.com>
This commit is contained in:
Alexander Onnikov
2025-07-31 21:31:42 +07:00
committed by GitHub
parent 3f2606b2bd
commit 4f2d510e2a
2 changed files with 23 additions and 1 deletions
+21
View File
@@ -568,6 +568,27 @@ export async function checkPermission (
const arePermissionsDisabled = getMetadata(core.metadata.DisablePermissions) ?? false
if (arePermissionsDisabled) return true
return await hasPermission(client, _id, _space, space)
}
export async function checkForbiddenPermission (
client: TxOperations,
_id: Ref<Permission>,
_space: Ref<TypedSpace>,
space?: TypedSpace
): Promise<boolean> {
const arePermissionsDisabled = getMetadata(core.metadata.DisablePermissions) ?? false
if (arePermissionsDisabled) return false
return await hasPermission(client, _id, _space, space)
}
async function hasPermission (
client: TxOperations,
_id: Ref<Permission>,
_space: Ref<TypedSpace>,
space?: TypedSpace
): Promise<boolean> {
space = space ?? (await client.findOne(core.class.TypedSpace, { _id: _space }))
const type = await client
.getModel()
@@ -15,6 +15,7 @@
import core, {
checkPermission,
checkForbiddenPermission,
getCurrentAccount,
toIdMap,
AccountRole,
@@ -50,7 +51,7 @@ export async function canDeleteObject (doc?: Doc | Doc[]): Promise<boolean> {
return !(
await Promise.all(
Array.from(targetSpaces.entries()).map(
async (s) => await checkPermission(client, core.permission.ForbidDeleteObject, s[0], s[1])
async (s) => await checkForbiddenPermission(client, core.permission.ForbidDeleteObject, s[0], s[1])
)
)
).some((r) => r)