diff --git a/lib/galaxy/managers/pages.py b/lib/galaxy/managers/pages.py index a961188a6e6..42519e99244 100644 --- a/lib/galaxy/managers/pages.py +++ b/lib/galaxy/managers/pages.py @@ -345,7 +345,7 @@ class PageManager(sharable.SharableModelManager[model.Page], UsesAnnotations): page = trans.sa_session.get(model.Page, id) if not page: raise exceptions.ObjectNotFound("Page not found") - page = base.security_check(trans, page, check_ownership=False, check_accessible=True) + page = base.security_check(trans, page, check_ownership=True, check_accessible=True) # Validate slug changes (only for non-history pages) if payload.slug is not None and payload.slug != page.slug: diff --git a/lib/galaxy_test/api/test_pages.py b/lib/galaxy_test/api/test_pages.py index 93c86c95266..077fbe9a305 100644 --- a/lib/galaxy_test/api/test_pages.py +++ b/lib/galaxy_test/api/test_pages.py @@ -498,6 +498,13 @@ steps: show_json = show_response.json() assert show_json["annotation"] == "newannotation" + def test_update_as_other_user(self): + response_json = self._create_valid_page_with_slug("pagetoupdateasother") + page_id = response_json["id"] + with self._different_user(): + update_response = self._update_page(page_id, "newannotation", "newslug", "newtitle", error_code=403) + assert update_response["err_msg"] == "Page is not owned by the current user" + def test_403_on_unowner_show(self): response_json = self._create_valid_page_as("others_page_show@bx.psu.edu", "otherspageshow") show_response = self._get(f"pages/{response_json['id']}")