Files
mattermost/server/channels
mattermost-code c93955ad7c Allow public permalink clicks to join when compliance is enabled (#38040)
* Allow getPostInfo join metadata when compliance is enabled

GET /posts/{id}/info was treating compliance as a content-read check
and returning 404 for public-channel non-members, so permalink clicks
never reached joinChannel. Return join metadata regardless of
compliance; content APIs and permalink previews stay gated.

Co-authored-by: maria.nunez <maria.nunez@mattermost.com>

* Move permalink preview sanitizer tests next to embed coverage

Keep compliance on/off permalink embed assertions in
TestSanitizePostMetadataForUser instead of the channel-mentions suite.

Co-authored-by: maria.nunez <maria.nunez@mattermost.com>

* Add guest GetPostInfo regression coverage with compliance enabled

Keep guests denied for public-channel join metadata when they are not
channel members, including after compliance is turned on.

Co-authored-by: maria.nunez <maria.nunez@mattermost.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: maria.nunez <maria.nunez@mattermost.com>
Co-authored-by: Mattermost Build <build@mattermost.com>
2026-08-26 14:55:36 -04:00
..
2026-04-01 13:03:36 +00:00

Server Channels Review Guidelines

When reviewing or writing code in the server channels package, focus on SQL query performance and API layer efficiency.

SQL Store Layer

  • Run EXPLAIN ANALYZE on new or modified queries against a large dataset before merging. A query that performs well on a 12M-post database may degrade significantly at 100M+ posts.
  • Watch for sequential scans on large tables. Ensure appropriate indexes exist for new query patterns.
  • When adding new queries to the store, check whether an existing query already fetches the needed data. Avoid duplicate round trips to the database.

API Layer

  • Minimize database round trips. If an endpoint calls a Get followed by a Delete on the same row, consider using DELETE ... RETURNING to combine them into a single query.
  • Don't add queries that are unnecessary for the operation. The most efficient work is the work you don't do.
  • When adding new API endpoints, add them to the load test tooling so performance can be validated under realistic concurrency.

Permissions and Security

  • Verify that new endpoints enforce appropriate permissions. Rely on the dedicated security review for thorough coverage, but flag anything obviously missing (e.g., an endpoint that skips permission checks entirely).