From 31776986e5dd892055811a3b18a74fab3c5337f0 Mon Sep 17 00:00:00 2001 From: shamoon <4887959+shamoon@users.noreply.github.com> Date: Wed, 7 Oct 2026 16:03:13 -0700 Subject: [PATCH] ai chat too --- src/documents/tests/test_api_document_versions.py | 12 ++++++++++++ src/documents/views.py | 10 ++++++++-- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/src/documents/tests/test_api_document_versions.py b/src/documents/tests/test_api_document_versions.py index 045677d0e..417aa4b16 100644 --- a/src/documents/tests/test_api_document_versions.py +++ b/src/documents/tests/test_api_document_versions.py @@ -1108,6 +1108,18 @@ class TestVersionActionPermissions(DirectoriesMixin, APITestCase): format="json", ) self.assertEqual(response.status_code, 403) + with ( + mock.patch("documents.views.AIConfig") as ai_config, + mock.patch("documents.views.stream_chat_with_documents") as chat, + ): + ai_config.return_value.ai_enabled = True + response = self.client.post( + "/api/documents/chat/", + {"q": "Version?", "document_id": self.version.pk}, + format="json", + ) + self.assertEqual(response.status_code, 403) + chat.assert_not_called() self.assertTrue(Note.objects.filter(pk=note.pk).exists()) self.assertFalse(ShareLink.objects.exists()) diff --git a/src/documents/views.py b/src/documents/views.py index 6eac94945..b729d1547 100644 --- a/src/documents/views.py +++ b/src/documents/views.py @@ -2443,11 +2443,17 @@ class ChatStreamingView(GenericAPIView[Any]): if doc_id: try: - document = Document.objects.get(id=doc_id) + document = Document.objects.select_related( + "root_document__owner", + ).get(id=doc_id) except Document.DoesNotExist: return HttpResponseBadRequest("Document not found") - if not has_perms_owner_aware(request.user, "view_document", document): + if not has_perms_owner_aware( + request.user, + "view_document", + get_root_document(document), + ): return HttpResponseForbidden("Insufficient permissions") documents = Document.objects.filter(pk=document.pk)