mirror of
https://github.com/suitenumerique/messages.git
synced 2026-09-30 05:34:55 +02:00
🐛(global) enforce full edit rights on thread mutations
A user with VIEWER MailboxAccess on a shared mailbox could still mutate threads that the mailbox had EDITOR ThreadAccess to: the permission check only looked at ThreadAccess.role, never at MailboxAccess.role. Both roles must now be satisfied (EDITOR on ThreadAccess AND a role in MAILBOX_ROLES_CAN_EDIT on MailboxAccess) for archive, spam, trash, label, split, refresh_summary and thread-event writes. Personal actions (unread, starred) intentionally stay open to any mailbox access since they only mutate the caller's own ThreadAccess row. The rule is centralised in ThreadAccessQuerySet.editable_by(user, mailbox_id) so viewsets and permission classes share a single source of truth, and exposed to the frontend via a new Thread.abilities.edit field consumed by use-ability, which gates the matching UI controls.
This commit is contained in:
@@ -9055,9 +9055,17 @@
|
||||
"events_count": {
|
||||
"type": "integer",
|
||||
"readOnly": true
|
||||
},
|
||||
"abilities": {
|
||||
"type": "object",
|
||||
"additionalProperties": {
|
||||
"type": "boolean"
|
||||
},
|
||||
"readOnly": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"abilities",
|
||||
"accesses",
|
||||
"active_messaged_at",
|
||||
"archived_messaged_at",
|
||||
|
||||
Reference in New Issue
Block a user