MCPcopy Create free account
hub / github.com/PerpetualSoftware/pad / requireItemVisible

Method requireItemVisible

internal/server/server.go:2375–2386  ·  view source on GitHub ↗

requireItemVisible checks that the item's collection is visible to the requesting user. For guests with item-level grants, also verifies that the specific item is granted (not just the collection). Writes a 404 and returns false if not. Callers should invoke this immediately after resolving an item

(w http.ResponseWriter, r *http.Request, workspaceID string, item *models.Item)

Source from the content-addressed store, hash-verified

2373// (e.g. handlers_ref_resolver.go) should use checkItemVisible directly with
2374// a manually-derived role.
2375func (s *Server) requireItemVisible(w http.ResponseWriter, r *http.Request, workspaceID string, item *models.Item) bool {
2376 visible, err := s.checkItemVisible(workspaceID, item, currentUser(r), workspaceRole(r), isBearerAuth(r))
2377 if err != nil {
2378 writeInternalError(w, err)
2379 return false
2380 }
2381 if !visible {
2382 writeError(w, http.StatusNotFound, "not_found", "Item not found")
2383 return false
2384 }
2385 return true
2386}
2387
2388// checkItemVisible is the context-free visibility decision. Returns (true,
2389// nil) when the (user, role) pair can see `item` under the same rules

Callers 15

handleListItemGrantsMethod · 0.95
handleCreateItemGrantMethod · 0.95
handleDeleteItemGrantMethod · 0.95
handleCreateWatchMethod · 0.95
handleDeleteWatchMethod · 0.95
handleGetItemLinksMethod · 0.95
handleCreateItemLinkMethod · 0.95
handleShowPlaybookMethod · 0.95
handleRunPlaybookMethod · 0.95
handlePushToItemMethod · 0.95

Calls 6

checkItemVisibleMethod · 0.95
currentUserFunction · 0.85
workspaceRoleFunction · 0.85
isBearerAuthFunction · 0.85
writeInternalErrorFunction · 0.85
writeErrorFunction · 0.85

Tested by

no test coverage detected