Writing delegates may add at the top of a locked account's Files
A shared account refuses top-level folders, so an organize or full delegate couldn't add anything to a locked account with no folders. A delegate who may write now can, as the owner could; the reconcile after the create grants it the new folder. Read delegates still can't (AL-6, AL-7).
This commit is contained in:
@@ -226,9 +226,14 @@ impl FileNodeCopy for Server {
|
||||
}
|
||||
};
|
||||
|
||||
if let Err(err) =
|
||||
validate_file_node_hierarchy(None, &file_node, is_shared, &cache, &created_folders)
|
||||
{
|
||||
// inbuxa: AL-7: a writing delegate may add at the top
|
||||
if let Err(err) = validate_file_node_hierarchy(
|
||||
None,
|
||||
&file_node,
|
||||
is_shared && !access_token.delegate_may_write(account_id),
|
||||
&cache,
|
||||
&created_folders,
|
||||
) {
|
||||
response.not_created.append(id, err);
|
||||
continue 'create;
|
||||
}
|
||||
@@ -362,7 +367,7 @@ impl FileNodeCopy for Server {
|
||||
);
|
||||
continue 'create;
|
||||
}
|
||||
} else if is_shared {
|
||||
} else if is_shared && !access_token.delegate_may_write(account_id) {
|
||||
response.not_created.append(
|
||||
id,
|
||||
SetError::forbidden()
|
||||
|
||||
@@ -149,9 +149,15 @@ impl FileNodeSet for Server {
|
||||
};
|
||||
|
||||
// Validate hierarchy
|
||||
if let Err(err) =
|
||||
validate_file_node_hierarchy(None, &file_node, is_shared, &cache, &created_folders)
|
||||
{
|
||||
// inbuxa: AL-7: a writing delegate may add at the top of a
|
||||
// locked account, which may hold no folders at all
|
||||
if let Err(err) = validate_file_node_hierarchy(
|
||||
None,
|
||||
&file_node,
|
||||
is_shared && !access_token.delegate_may_write(account_id),
|
||||
&cache,
|
||||
&created_folders,
|
||||
) {
|
||||
response.not_created.append(id, err);
|
||||
continue 'create;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user