fix: who may mark an account private is decided for every door - #943
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Who may mark an account private (
isPrivate) or private to its group (isPrivateGroup) was decided inAccountForm::constrainPrivacyToPermission(), and only the web goes through a form. The allowed callers are:isAccPrivate()isAccPrivateGroup()The API's
account/createandaccount/editput the caller'sprivate/privateGroupstraight into the row. So any token with edit access to an account could make it private without the permission, or strip privacy from one that had it. That matters more than it sounds:AccountAcltests privacy before the administrator branch, so a private account disappears for account administrators too.Change
Account::privacyAllowedFor(), now applied by the service on every write:create(),update(), and the history restore that already had its own copy. The form's copy is removed rather than kept alongside, so the web and the API can't drift apart.Tests
AccountTestcases:Mutation-verified: