chore(server): relax list session permission (#13268)
fix AI-326 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Adjusted permission checks for viewing histories and chats to require read access instead of update access on documents. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
@@ -37,7 +37,7 @@ import {
|
|||||||
import { CurrentUser } from '../../core/auth';
|
import { CurrentUser } from '../../core/auth';
|
||||||
import { Admin } from '../../core/common';
|
import { Admin } from '../../core/common';
|
||||||
import { DocReader } from '../../core/doc';
|
import { DocReader } from '../../core/doc';
|
||||||
import { AccessController } from '../../core/permission';
|
import { AccessController, DocAction } from '../../core/permission';
|
||||||
import { UserType } from '../../core/user';
|
import { UserType } from '../../core/user';
|
||||||
import type { ListSessionOptions, UpdateChatSession } from '../../models';
|
import type { ListSessionOptions, UpdateChatSession } from '../../models';
|
||||||
import { CopilotCronJobs } from './cron';
|
import { CopilotCronJobs } from './cron';
|
||||||
@@ -420,7 +420,8 @@ export class CopilotResolver {
|
|||||||
|
|
||||||
private async assertPermission(
|
private async assertPermission(
|
||||||
user: CurrentUser,
|
user: CurrentUser,
|
||||||
options: { workspaceId?: string | null; docId?: string | null }
|
options: { workspaceId?: string | null; docId?: string | null },
|
||||||
|
fallbackAction?: DocAction
|
||||||
) {
|
) {
|
||||||
const { workspaceId, docId } = options;
|
const { workspaceId, docId } = options;
|
||||||
if (!workspaceId) {
|
if (!workspaceId) {
|
||||||
@@ -431,7 +432,7 @@ export class CopilotResolver {
|
|||||||
.user(user.id)
|
.user(user.id)
|
||||||
.doc({ workspaceId, docId })
|
.doc({ workspaceId, docId })
|
||||||
.allowLocal()
|
.allowLocal()
|
||||||
.assert('Doc.Update');
|
.assert(fallbackAction ?? 'Doc.Update');
|
||||||
} else {
|
} else {
|
||||||
await this.ac
|
await this.ac
|
||||||
.user(user.id)
|
.user(user.id)
|
||||||
@@ -510,7 +511,7 @@ export class CopilotResolver {
|
|||||||
if (!workspaceId) {
|
if (!workspaceId) {
|
||||||
return [];
|
return [];
|
||||||
} else {
|
} else {
|
||||||
await this.assertPermission(user, { workspaceId, docId });
|
await this.assertPermission(user, { workspaceId, docId }, 'Doc.Read');
|
||||||
}
|
}
|
||||||
|
|
||||||
const histories = await this.chatSession.list(
|
const histories = await this.chatSession.list(
|
||||||
@@ -540,7 +541,7 @@ export class CopilotResolver {
|
|||||||
if (!workspaceId) {
|
if (!workspaceId) {
|
||||||
return paginate([], 'updatedAt', pagination, 0);
|
return paginate([], 'updatedAt', pagination, 0);
|
||||||
} else {
|
} else {
|
||||||
await this.assertPermission(user, { workspaceId, docId });
|
await this.assertPermission(user, { workspaceId, docId }, 'Doc.Read');
|
||||||
}
|
}
|
||||||
|
|
||||||
const finalOptions = Object.assign(
|
const finalOptions = Object.assign(
|
||||||
|
|||||||
Reference in New Issue
Block a user