requireItemVisible checks that the item's collection is visible to the requesting user. For guests with item-level grants, also verifies that the specific item is granted (not just the collection). Writes a 404 and returns false if not. Callers should invoke this immediately after resolving an item
(w http.ResponseWriter, r *http.Request, workspaceID string, item *models.Item)
| 2373 | // (e.g. handlers_ref_resolver.go) should use checkItemVisible directly with |
| 2374 | // a manually-derived role. |
| 2375 | func (s *Server) requireItemVisible(w http.ResponseWriter, r *http.Request, workspaceID string, item *models.Item) bool { |
| 2376 | visible, err := s.checkItemVisible(workspaceID, item, currentUser(r), workspaceRole(r), isBearerAuth(r)) |
| 2377 | if err != nil { |
| 2378 | writeInternalError(w, err) |
| 2379 | return false |
| 2380 | } |
| 2381 | if !visible { |
| 2382 | writeError(w, http.StatusNotFound, "not_found", "Item not found") |
| 2383 | return false |
| 2384 | } |
| 2385 | return true |
| 2386 | } |
| 2387 | |
| 2388 | // checkItemVisible is the context-free visibility decision. Returns (true, |
| 2389 | // nil) when the (user, role) pair can see `item` under the same rules |
no test coverage detected