Files
paperless-ngx/src/documents
stumpylog 7bdc407ed9 Fix: authorize document versions by their root in the single-object permission check
has_perms_owner_aware judged a document by its own owner and grants, so each
endpoint that fetches a document itself had to remember to map a version to
its root document first, and one that forgot, like the more-like-this search
filter, authorized by a stale version owner.

The check now maps a Document to its root before looking at the owner and the
guardian grants, matching what permitted_document_ids does for id sets. The
eight call sites that mapped the document themselves pass it straight through.
The DRF object permission class needs no change because the document viewset
only ever serves root documents.
2026-10-09 14:43:34 -07:00
..
2026-09-01 07:56:38 -07:00
2026-05-26 16:46:23 +00:00
2026-09-01 07:56:38 -07:00
2026-05-20 08:54:00 -07:00