feat(server): permission check for workspace doc match (#12139)
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Bug Fixes** - Improved permission checks to ensure users only see document chunks they have read access to. - Enhanced error handling for clearer and more user-friendly error messages. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
@@ -710,28 +710,44 @@ export class CopilotContextResolver {
|
|||||||
return [];
|
return [];
|
||||||
}
|
}
|
||||||
|
|
||||||
const session = await this.context.get(context.id);
|
|
||||||
await this.ac
|
|
||||||
.user(user.id)
|
|
||||||
.workspace(session.workspaceId)
|
|
||||||
.allowLocal()
|
|
||||||
.assert('Workspace.Copilot');
|
|
||||||
const allowEmbedding = await this.models.workspace.allowEmbedding(
|
|
||||||
session.workspaceId
|
|
||||||
);
|
|
||||||
if (!allowEmbedding) {
|
|
||||||
return [];
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
return await session.matchWorkspaceChunks(
|
const session = await this.context.get(context.id);
|
||||||
|
await this.ac
|
||||||
|
.user(user.id)
|
||||||
|
.workspace(session.workspaceId)
|
||||||
|
.allowLocal()
|
||||||
|
.assert('Workspace.Copilot');
|
||||||
|
const allowEmbedding = await this.models.workspace.allowEmbedding(
|
||||||
|
session.workspaceId
|
||||||
|
);
|
||||||
|
if (!allowEmbedding) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
const chunks = await session.matchWorkspaceChunks(
|
||||||
content,
|
content,
|
||||||
limit,
|
limit,
|
||||||
this.getSignal(ctx.req),
|
this.getSignal(ctx.req),
|
||||||
scopedThreshold,
|
scopedThreshold,
|
||||||
threshold
|
threshold
|
||||||
);
|
);
|
||||||
|
const docsMap = await Promise.all(
|
||||||
|
chunks.map(c =>
|
||||||
|
this.ac
|
||||||
|
.user(user.id)
|
||||||
|
.workspace(session.workspaceId)
|
||||||
|
.doc(c.docId)
|
||||||
|
.can('Doc.Read')
|
||||||
|
.then(ret => [c.docId, ret] as const)
|
||||||
|
)
|
||||||
|
).then(r => new Map(r));
|
||||||
|
|
||||||
|
return chunks.filter(c => docsMap.get(c.docId));
|
||||||
} catch (e: any) {
|
} catch (e: any) {
|
||||||
|
// passthrough user friendly error
|
||||||
|
if (e instanceof UserFriendlyError) {
|
||||||
|
throw e;
|
||||||
|
}
|
||||||
throw new CopilotFailedToMatchContext({
|
throw new CopilotFailedToMatchContext({
|
||||||
contextId: context.id,
|
contextId: context.id,
|
||||||
// don't record the large content
|
// don't record the large content
|
||||||
|
|||||||
Reference in New Issue
Block a user