Resolves Issue #1773, Additional Validation of User Authorization on Conversation Edits#1808
Merged
Conversation
…ized to make changes
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes Issue #1773
Summary
Conversation edits didn't properly differentiate between a regular user and a Secretariat user, preventing Secretariat users from editing or moderating a conversation that they didn't author. We now check
isSecretariatas part of the authorization evaluation, to allow them to edit/moderate as expected.Additionally, users that were no longer part of an org but still had a valid token, could edit old conversations that they were previously a part of. We now check the org associated with the user's active session against the org that owns the conversation itself. If there is a mismatch, the user is not allowed to make edits.
Important Changes
src/controller/registry-org.controller/registry-org.controller.jsisSecretariatto ensure that Secretariat users can edit or moderate any conversationTesting
Steps to manually test updated functionality, if possible