refac: calendar event tools use the calendar's access check (#31537)

Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does.
This commit is contained in:
Classic298 2026-09-30 17:29:19 +02:00 • committed by GitHub
parent 8600ab9fa7
commit 52533c5675
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -4413,10 +4413,10 @@ async def update_calendar_event(
return JSONCodec.dumps({'error': 'Event not found'})
# Check write access to the event's calendar
if event.user_id != user_id and __user__.get('role') != 'admin':
cal = await Calendars.get_calendar_by_id(event.calendar_id)
if not cal:
return JSONCodec.dumps({'error': 'Access denied'})
cal = await Calendars.get_calendar_by_id(event.calendar_id)
if not cal:
return JSONCodec.dumps({'error': 'Access denied'})
if cal.user_id != user_id and __user__.get('role') != 'admin':
user_group_ids = [g.id for g in await Groups.get_groups_by_member_id(user_id)]
if not await AccessGrants.has_access(
user_id=user_id,
@ -4517,10 +4517,10 @@ async def delete_calendar_event(
return JSONCodec.dumps({'error': 'Event not found'})
# Check write access
if event.user_id != user_id and __user__.get('role') != 'admin':
cal = await Calendars.get_calendar_by_id(event.calendar_id)
if not cal:
return JSONCodec.dumps({'error': 'Access denied'})
cal = await Calendars.get_calendar_by_id(event.calendar_id)
if not cal:
return JSONCodec.dumps({'error': 'Access denied'})
if cal.user_id != user_id and __user__.get('role') != 'admin':
user_group_ids = [g.id for g in await Groups.get_groups_by_member_id(user_id)]
if not await AccessGrants.has_access(
user_id=user_id,