🐛(global) enforce full edit rights on thread mutations

A user with VIEWER MailboxAccess on a shared mailbox could still mutate
threads that the mailbox had EDITOR ThreadAccess to: the permission
check only looked at ThreadAccess.role, never at MailboxAccess.role.

Both roles must now be satisfied (EDITOR on ThreadAccess AND a role in
MAILBOX_ROLES_CAN_EDIT on MailboxAccess) for archive, spam, trash,
label, split, refresh_summary and thread-event writes. Personal actions
(unread, starred) intentionally stay open to any mailbox access since
they only mutate the caller's own ThreadAccess row.

The rule is centralised in ThreadAccessQuerySet.editable_by(user,
mailbox_id) so viewsets and permission classes share a single source of
truth, and exposed to the frontend via a new Thread.abilities.edit
field consumed by use-ability, which gates the matching UI controls.
This commit is contained in:
jbpenrath
2026-04-14 23:08:13 +02:00
parent 13d34c213f
commit 01b45a69fb
37 changed files with 1155 additions and 150 deletions
+8
View File
@@ -9055,9 +9055,17 @@
"events_count": {
"type": "integer",
"readOnly": true
},
"abilities": {
"type": "object",
"additionalProperties": {
"type": "boolean"
},
"readOnly": true
}
},
"required": [
"abilities",
"accesses",
"active_messaged_at",
"archived_messaged_at",