mirror of
https://github.com/paperless-ngx/paperless-ngx.git
synced 2026-10-11 18:47:13 +00:00
Fix: authorize document versions by their root in the single-object permission check
has_perms_owner_aware judged a document by its own owner and grants, so each endpoint that fetches a document itself had to remember to map a version to its root document first, and one that forgot, like the more-like-this search filter, authorized by a stale version owner. The check now maps a Document to its root before looking at the owner and the guardian grants, matching what permitted_document_ids does for id sets. The eight call sites that mapped the document themselves pass it straight through. The DRF object permission class needs no change because the document viewset only ever serves root documents.
This commit is contained in:
1 parent
01e1e76f91
commit
7bdc407ed9
4 files changed
+103
-9
No files matched your search
@@ -90,7 +90,6 @@ from documents.templating.utils import convert_format_str_to_template_format
|
||||
from documents.templating.workflows import validate_workflow_template
|
||||
from documents.validators import uri_validator
|
||||
from documents.validators import url_validator
|
||||
from documents.versioning import get_root_document
|
||||
from documents.versioning import has_prefetched_effective_content
|
||||
from documents.versioning import sort_versions_newest_first
|
||||
|
||||
@@ -2895,7 +2894,7 @@ class ShareLinkSerializer(OwnedObjectSerializer):
|
||||
and has_perms_owner_aware(
|
||||
self.user,
|
||||
"view_document",
|
||||
get_root_document(document),
|
||||
document,
|
||||
)
|
||||
):
|
||||
return document
|
||||
|
||||
Reference in new issue
Block a user