fix: update get_user_list method to include user_id for workspace validation - #6586
Merged
Merged
Conversation
Contributor
Author
|
Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information |
There was a problem hiding this comment.
Pull request overview
This PR updates the workspace-scoped user listing endpoint to pass the current user’s ID into the serializer, enabling validation that the requesting user belongs to the target workspace before returning users.
Changes:
- Updated
WorkspaceUserListViewto passrequest.user.idintoget_user_list. - Changed
UserManageSerializer.get_user_listsignature and added workspace-membership validation logic. - Minor refactors/formatting in
apps/users/serializers/user.py(imports and a resource-mapping helper).
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| apps/users/views/user.py | Passes current user ID into the workspace user-list serializer call. |
| apps/users/serializers/user.py | Adds user_id parameter to get_user_list and implements workspace membership validation logic. |
Suppressed comments (2)
apps/users/serializers/user.py:566
get_user_listis currently granting admin-like access based on a hard-coded UUID and, in the EE/workspace-mapping branch, will return an empty list for users that are authorized by@has_permissions(e.g.,RoleConstants.ADMIN) but not explicitly mapped to the workspace. Derive anis_adminflag from the actual user record/role and use it consistently to bypass the workspace-membership check, instead of relying on a literal UUID comparison inside the query logic.
def get_user_list(self, user_id,workspace_id, nick_name):
"""
获取用户列表
:param workspace_id: 工作空间ID
:return: 用户列表
apps/users/serializers/user.py:829
defaultdictis already imported at module scope, so re-importing it inside_get_resource_mapsis redundant. Remove the local import to keep imports centralized and avoid unnecessary per-call work.
from collections import defaultdict
from application.models import Application, ApplicationFolder
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| from django.db import transaction | ||
| from django.db.models import Q, QuerySet | ||
| from django.utils import translation | ||
| from django.utils.translation import get_language, to_locale |
| def get(self, request: Request, workspace_id): | ||
| nick_name = request.query_params.get('nick_name', None) | ||
| return result.success(UserManageSerializer().get_user_list(workspace_id, nick_name)) | ||
| return result.success(UserManageSerializer().get_user_list(str(request.user.id),workspace_id, nick_name)) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix: update get_user_list method to include user_id for workspace validation