mirror of
https://github.com/mattermost/mattermost.git
synced 2026-09-01 15:00:08 +08:00
c93955ad7c
* Allow getPostInfo join metadata when compliance is enabled
GET /posts/{id}/info was treating compliance as a content-read check
and returning 404 for public-channel non-members, so permalink clicks
never reached joinChannel. Return join metadata regardless of
compliance; content APIs and permalink previews stay gated.
Co-authored-by: maria.nunez <maria.nunez@mattermost.com>
* Move permalink preview sanitizer tests next to embed coverage
Keep compliance on/off permalink embed assertions in
TestSanitizePostMetadataForUser instead of the channel-mentions suite.
Co-authored-by: maria.nunez <maria.nunez@mattermost.com>
* Add guest GetPostInfo regression coverage with compliance enabled
Keep guests denied for public-channel join metadata when they are not
channel members, including after compliance is turned on.
Co-authored-by: maria.nunez <maria.nunez@mattermost.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: maria.nunez <maria.nunez@mattermost.com>
Co-authored-by: Mattermost Build <build@mattermost.com>
Server Channels Review Guidelines
When reviewing or writing code in the server channels package, focus on SQL query performance and API layer efficiency.
SQL Store Layer
- Run
EXPLAIN ANALYZEon new or modified queries against a large dataset before merging. A query that performs well on a 12M-post database may degrade significantly at 100M+ posts. - Watch for sequential scans on large tables. Ensure appropriate indexes exist for new query patterns.
- When adding new queries to the store, check whether an existing query already fetches the needed data. Avoid duplicate round trips to the database.
API Layer
- Minimize database round trips. If an endpoint calls a
Getfollowed by aDeleteon the same row, consider usingDELETE ... RETURNINGto combine them into a single query. - Don't add queries that are unnecessary for the operation. The most efficient work is the work you don't do.
- When adding new API endpoints, add them to the load test tooling so performance can be validated under realistic concurrency.
Permissions and Security
- Verify that new endpoints enforce appropriate permissions. Rely on the dedicated security review for thorough coverage, but flag anything obviously missing (e.g., an endpoint that skips permission checks entirely).