mirror of
https://github.com/open-webui/open-webui.git
synced 2026-10-06 02:48:04 +00:00
refac: calendar event tools use the calendar's access check (#31537)
Editing or deleting a calendar event through the chat tools now checks access to the event's calendar the same way the calendar API does.
This commit is contained in:
parent
8600ab9fa7
commit
52533c5675
1 changed files with 8 additions and 8 deletions
|
|
@ -4413,10 +4413,10 @@ async def update_calendar_event(
|
|||
return JSONCodec.dumps({'error': 'Event not found'})
|
||||
|
||||
# Check write access to the event's calendar
|
||||
if event.user_id != user_id and __user__.get('role') != 'admin':
|
||||
cal = await Calendars.get_calendar_by_id(event.calendar_id)
|
||||
if not cal:
|
||||
return JSONCodec.dumps({'error': 'Access denied'})
|
||||
cal = await Calendars.get_calendar_by_id(event.calendar_id)
|
||||
if not cal:
|
||||
return JSONCodec.dumps({'error': 'Access denied'})
|
||||
if cal.user_id != user_id and __user__.get('role') != 'admin':
|
||||
user_group_ids = [g.id for g in await Groups.get_groups_by_member_id(user_id)]
|
||||
if not await AccessGrants.has_access(
|
||||
user_id=user_id,
|
||||
|
|
@ -4517,10 +4517,10 @@ async def delete_calendar_event(
|
|||
return JSONCodec.dumps({'error': 'Event not found'})
|
||||
|
||||
# Check write access
|
||||
if event.user_id != user_id and __user__.get('role') != 'admin':
|
||||
cal = await Calendars.get_calendar_by_id(event.calendar_id)
|
||||
if not cal:
|
||||
return JSONCodec.dumps({'error': 'Access denied'})
|
||||
cal = await Calendars.get_calendar_by_id(event.calendar_id)
|
||||
if not cal:
|
||||
return JSONCodec.dumps({'error': 'Access denied'})
|
||||
if cal.user_id != user_id and __user__.get('role') != 'admin':
|
||||
user_group_ids = [g.id for g in await Groups.get_groups_by_member_id(user_id)]
|
||||
if not await AccessGrants.has_access(
|
||||
user_id=user_id,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue