Merge pull request #22911 from ahmedhamidawan/make_unowned_pages_uneditable

[26.1] Make unowned but accessible pages uneditable
This commit is contained in:
Marius van den Beek
2026-06-15 11:09:43 +02:00
committed by GitHub
2 changed files with 8 additions and 1 deletions
+1 -1
View File
@@ -345,7 +345,7 @@ class PageManager(sharable.SharableModelManager[model.Page], UsesAnnotations):
page = trans.sa_session.get(model.Page, id)
if not page:
raise exceptions.ObjectNotFound("Page not found")
page = base.security_check(trans, page, check_ownership=False, check_accessible=True)
page = base.security_check(trans, page, check_ownership=True, check_accessible=True)
# Validate slug changes (only for non-history pages)
if payload.slug is not None and payload.slug != page.slug:
+7
View File
@@ -498,6 +498,13 @@ steps:
show_json = show_response.json()
assert show_json["annotation"] == "newannotation"
def test_update_as_other_user(self):
response_json = self._create_valid_page_with_slug("pagetoupdateasother")
page_id = response_json["id"]
with self._different_user():
update_response = self._update_page(page_id, "newannotation", "newslug", "newtitle", error_code=403)
assert update_response["err_msg"] == "Page is not owned by the current user"
def test_403_on_unowner_show(self):
response_json = self._create_valid_page_as("others_page_show@bx.psu.edu", "otherspageshow")
show_response = self._get(f"pages/{response_json['id']}")