Enforce document/binder collection scope in addItem

FixDocsService
Shipped
August 6, 2026 at 7:57 AM UTC
Author
Kamo
Commit
8db7fc5

BinderService.addItem checked read access and refused VAULT/LOAN documents, but never compared the document's own collection to the binder's, so a hand-crafted request could still cross-file a document from another collection into a binder - the UI-only fix left the API open.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing