Fix API Get channels for a user returns users' dm channels with blank teamid (#4748)
* fix API Get channels for a user returns users' dm channels with blank team ID add check in the context.go add suggestion made adjustment per review and support from @joram * update tests * add check if needd user or admin permissions * update per review
Этот коммит содержится в:
коммит произвёл
Corey Hulen
родитель
92b2810d84
Коммит
b9092ca2f5
@@ -221,6 +221,11 @@ func (h handler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||
SetStatusOnline(c.Session.UserId, c.Session.Id, false)
|
||||
}
|
||||
|
||||
if c.Err == nil && (h.requireUser || h.requireSystemAdmin) {
|
||||
//check if teamId exist
|
||||
c.CheckTeamId()
|
||||
}
|
||||
|
||||
if c.Err == nil {
|
||||
h.handleFunc(c, w, r)
|
||||
}
|
||||
@@ -575,3 +580,18 @@ func InvalidateAllCaches() {
|
||||
store.ClearUserCaches()
|
||||
store.ClearPostCaches()
|
||||
}
|
||||
|
||||
func (c *Context) CheckTeamId() {
|
||||
if c.TeamId != "" && c.Session.GetTeamByTeamId(c.TeamId) == nil {
|
||||
if HasPermissionToContext(c, model.PERMISSION_MANAGE_SYSTEM) {
|
||||
if result := <-Srv.Store.Team().Get(c.TeamId); result.Err != nil {
|
||||
c.Err = result.Err
|
||||
c.Err.StatusCode = http.StatusBadRequest
|
||||
return
|
||||
}
|
||||
} else {
|
||||
// just return because it fail on the HasPermissionToContext and the error is already on the Context c.Err
|
||||
return
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Ссылка в новой задаче
Block a user