fix: include team admins in project access check

The get_project endpoint's team-membership check only iterated
team.members_with_roles, so users present in team.admins but not
members_with_roles were denied access. Restore the admin check to
match _check_user_permission_for_project.
This commit is contained in:
Cursor Agent 2026-05-06 23:38:27 +00:00 • committed by mateo-berri
parent c5e5fc9c7a
commit b2e3d6ed2b

View file

@ -877,15 +877,18 @@ async def project_info(
)
if team:
caller_user_id = user_api_key_dict.user_id
for m in team.members_with_roles or []:
m_user_id = (
m.get("user_id")
if isinstance(m, dict)
else getattr(m, "user_id", None)
)
if m_user_id == caller_user_id:
is_team_member = True
break
if team.admins and caller_user_id in team.admins:
is_team_member = True
else:
for m in team.members_with_roles or []:
m_user_id = (
m.get("user_id")
if isinstance(m, dict)
else getattr(m, "user_id", None)
)
if m_user_id == caller_user_id:
is_team_member = True
break
if not (is_admin or is_team_member):
raise HTTPException(