refactor: check shared chat access before loading the snapshot on clone (#30388)

The clone endpoint now resolves and checks the share before reading its snapshot, matching the order used by the shared chat view endpoint.
This commit is contained in:
Classic298 2026-09-26 05:20:14 +02:00 • committed by GitHub
parent c402acb404
commit 42cd4f0ec0
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1848,18 +1848,6 @@ async def clone_shared_chat_by_id(
):
await require_chat_import_permission(request, user, db)
chat = await Chats.get_chat_by_share_id(id, db=db)
# Fallback: admins can also access any chat directly by chat ID
if not chat and user.role == 'admin' and ENABLE_ADMIN_CHAT_ACCESS:
chat = await Chats.get_chat_by_id(id, db=db)
if not chat:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail=ERROR_MESSAGES.NOT_FOUND,
)
# Enforce access grants (owner and admins bypass)
shared = await SharedChats.get_by_id(id, db=db)
if shared and user.role != 'admin' and shared.user_id != user.id:
@ -1876,6 +1864,18 @@ async def clone_shared_chat_by_id(
detail=ERROR_MESSAGES.ACCESS_PROHIBITED,
)
chat = await Chats.get_chat_by_share_id(id, db=db) if shared else None
# Fallback: admins can also access any chat directly by chat ID
if not chat and user.role == 'admin' and ENABLE_ADMIN_CHAT_ACCESS:
chat = await Chats.get_chat_by_id(id, db=db)
if not chat:
raise HTTPException(
status_code=status.HTTP_401_UNAUTHORIZED,
detail=ERROR_MESSAGES.NOT_FOUND,
)
updated_chat = {
**chat.chat,
'originalChatId': chat.id,