KamoCRM

UpdateDocType now requires the doc type to belong to the document's own org

Fixkamo-shared-library
Shipped
September 23, 2026 at 8:56 AM UTC
Author
Kamo
Commit
4463686

ImageService.updateDocType loaded the target ImgDocType by UUID alone; requireEditableAndOwned proves the caller may edit the Img, but says nothing about whose taxonomy docTypeId names. A member with EDIT_DOCUMENTS on their own document could file it under a doc type belonging to a different organization entirely, if they could name its UUID. Refuse the assignment unless docType.organization matches img.organization.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing