filterUserGrantsForCaller narrows collGrants/itemGrants — the TARGET user's grants, already loaded by the caller — down to what the CALLER can see. Only meaningful when caller != target; handleListUserGrants skips calling this for self-queries (a user can always see their own grants). BUG-1928: han
(r *http.Request, workspaceID string, collGrants []models.CollectionGrant, itemGrants []models.ItemGrant)
| 2283 | // call (state-agnostic; no deleted_at filter) rather than N per-grant |
| 2284 | // lookups. |
| 2285 | func (s *Server) filterUserGrantsForCaller(r *http.Request, workspaceID string, collGrants []models.CollectionGrant, itemGrants []models.ItemGrant) ([]models.CollectionGrant, []models.ItemGrant, error) { |
| 2286 | fullCollIDs, grantedItemIDs, err := s.guestResourceFilter(r, workspaceID) |
| 2287 | if err != nil { |
| 2288 | return nil, nil, err |
| 2289 | } |
| 2290 | if fullCollIDs == nil && grantedItemIDs == nil { |
| 2291 | // Unrestricted caller (admin/cookie session, or a member with |
| 2292 | // full collection access) — no filtering, and no further store |
| 2293 | // calls needed. |
| 2294 | return collGrants, itemGrants, nil |
| 2295 | } |
| 2296 | |
| 2297 | filteredColl := make([]models.CollectionGrant, 0, len(collGrants)) |
| 2298 | for _, g := range collGrants { |
| 2299 | if isCollectionVisible(g.CollectionID, fullCollIDs) { |
| 2300 | filteredColl = append(filteredColl, g) |
| 2301 | } |
| 2302 | } |
| 2303 | |
| 2304 | filteredItem := make([]models.ItemGrant, 0, len(itemGrants)) |
| 2305 | if len(itemGrants) > 0 { |
| 2306 | itemIDs := make([]string, len(itemGrants)) |
| 2307 | for i, g := range itemGrants { |
| 2308 | itemIDs[i] = g.ItemID |
| 2309 | } |
| 2310 | refs, err := s.store.GetItemCollectionRefs(workspaceID, itemIDs) |
| 2311 | if err != nil { |
| 2312 | return nil, nil, err |
| 2313 | } |
| 2314 | collByItem := make(map[string]string, len(refs)) |
| 2315 | for _, ref := range refs { |
| 2316 | collByItem[ref.ID] = ref.CollectionID |
| 2317 | } |
| 2318 | for _, g := range itemGrants { |
| 2319 | collID, ok := collByItem[g.ItemID] |
| 2320 | if !ok { |
| 2321 | // item_grants.item_id is ON DELETE CASCADE, so a grant |
| 2322 | // row can't outlive its item — this should be |
| 2323 | // unreachable. Exclude defensively rather than show a |
| 2324 | // grant with no resolvable parent. |
| 2325 | continue |
| 2326 | } |
| 2327 | item := &models.Item{ID: g.ItemID, CollectionID: collID} |
| 2328 | if s.isItemVisibleToGuest(r, workspaceID, item, fullCollIDs, grantedItemIDs) { |
| 2329 | filteredItem = append(filteredItem, g) |
| 2330 | } |
| 2331 | } |
| 2332 | } |
| 2333 | |
| 2334 | return filteredColl, filteredItem, nil |
| 2335 | } |
| 2336 | |
| 2337 | // requireEditPermission checks if the user has edit access to the given item. |
| 2338 | // For regular members (editor/owner), this uses the standard role check. |
no test coverage detected