Enforce the doc-share search rights server-side

FixSecurityService
Ya
14 Agosti 2026, 22:22 UTC
Mwandishi
Kamo
Ahadi ya
34059bc

/members-subscribers and /team-members-contractors enumerate the organisation's people — names and ids — to fill the document-share autocomplete, and required only a session. ShareDocumentDialog was the only thing applying the rule, and both routes are reachable directly through APIService. Mirrors the dialog: a team member may always search, anyone else needs the matching SHARE_DOCS_SEARCH_* right. memberTypeUnknown is deliberately not mirrored — it is a legacy-session fallback and would make the gate permanently bypassable. The caller's type is resolved from the database rather than a session key, because the type is an authorization input here and the database is the authority on it. No lockout: the browser already refuses these calls for members without the right, so the only traffic newly rejected is a direct API call that was bypassing the rule. Both handlers were on the unguarded-endpoint ratchet baseline; removed, taking it from 397 to 395. That test failing was the correct signal — it requires the count to actually fall rather than let the file grow stale.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei