mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Merge pull request #22911 from ahmedhamidawan/make_unowned_pages_uneditable
[26.1] Make unowned but accessible pages uneditable
This commit is contained in:
@@ -345,7 +345,7 @@ class PageManager(sharable.SharableModelManager[model.Page], UsesAnnotations):
|
||||
page = trans.sa_session.get(model.Page, id)
|
||||
if not page:
|
||||
raise exceptions.ObjectNotFound("Page not found")
|
||||
page = base.security_check(trans, page, check_ownership=False, check_accessible=True)
|
||||
page = base.security_check(trans, page, check_ownership=True, check_accessible=True)
|
||||
|
||||
# Validate slug changes (only for non-history pages)
|
||||
if payload.slug is not None and payload.slug != page.slug:
|
||||
|
||||
@@ -498,6 +498,13 @@ steps:
|
||||
show_json = show_response.json()
|
||||
assert show_json["annotation"] == "newannotation"
|
||||
|
||||
def test_update_as_other_user(self):
|
||||
response_json = self._create_valid_page_with_slug("pagetoupdateasother")
|
||||
page_id = response_json["id"]
|
||||
with self._different_user():
|
||||
update_response = self._update_page(page_id, "newannotation", "newslug", "newtitle", error_code=403)
|
||||
assert update_response["err_msg"] == "Page is not owned by the current user"
|
||||
|
||||
def test_403_on_unowner_show(self):
|
||||
response_json = self._create_valid_page_as("others_page_show@bx.psu.edu", "otherspageshow")
|
||||
show_response = self._get(f"pages/{response_json['id']}")
|
||||
|
||||
Reference in New Issue
Block a user