fix: members can be added to or removed from a direct message through the API (#31575)

The person who started a direct message could add or remove people through the API, although the app only offers this in group channels. Someone added this way could read the whole earlier conversation, and because the original pair no longer matched the conversation, their next message opened a second, empty direct message. Changing the members of a direct message now answers with a 403.

Fixes #31570
This commit is contained in:
Classic298 2026-09-30 17:03:32 +02:00 • committed by GitHub
parent fa66b0f306
commit 3d70d43a1c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -642,6 +642,9 @@ async def add_members_by_id(
if channel.user_id != user.id and user.role != 'admin':
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
if channel.type == 'dm':
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
try:
memberships = await Channels.add_members_to_channel(
channel.id, user.id, form_data.user_ids, form_data.group_ids, db=db
@ -686,9 +689,12 @@ async def remove_members_by_id(
if channel.user_id != user.id and user.role != 'admin':
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
if channel.type == 'dm':
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())
try:
deleted = await Channels.remove_members_from_channel(channel.id, form_data.user_ids, db=db)
if channel.type in ['group', 'dm']:
if channel.type == 'group':
await leave_room_for_users(f'channel:{channel.id}', form_data.user_ids)
await publish_event(