mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
fix(custom-blocks): dedupe redundant workspace lookup in POST admin check (#5429)
hasWorkspaceAdminAccess + a separate getWorkspaceWithOwner call each independently re-fetched the workspace row for the same (userId, workspaceId) pair. Consolidated into a single checkWorkspaceAccess call, matching the pattern the GET handler in this same file already uses. access.canAdmin is logically identical to hasWorkspaceAdminAccess's result (admin is the top PERMISSION_RANK, nothing else satisfies it) — no behavior change, one fewer DB round-trip per publish request.
This commit is contained in:
@@ -17,11 +17,7 @@ import {
|
||||
listCustomBlocksWithInputs,
|
||||
publishCustomBlock,
|
||||
} from '@/lib/workflows/custom-blocks/operations'
|
||||
import {
|
||||
checkWorkspaceAccess,
|
||||
getWorkspaceWithOwner,
|
||||
hasWorkspaceAdminAccess,
|
||||
} from '@/lib/workspaces/permissions/utils'
|
||||
import { checkWorkspaceAccess } from '@/lib/workspaces/permissions/utils'
|
||||
|
||||
const logger = createLogger('CustomBlocksAPI')
|
||||
|
||||
@@ -84,18 +80,18 @@ export const POST = withRouteHandler(async (request: NextRequest) => {
|
||||
const userId = session.user.id
|
||||
const { workspaceId, workflowId, name, description, iconUrl, exposedOutputs } = parsed.data.body
|
||||
|
||||
if (!(await hasWorkspaceAdminAccess(userId, workspaceId))) {
|
||||
const access = await checkWorkspaceAccess(workspaceId, userId)
|
||||
if (!access.canAdmin) {
|
||||
return NextResponse.json({ error: 'Admin permissions required' }, { status: 403 })
|
||||
}
|
||||
|
||||
const ws = await getWorkspaceWithOwner(workspaceId)
|
||||
if (!ws?.organizationId) {
|
||||
const organizationId = access.workspace?.organizationId
|
||||
if (!organizationId) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Publishing a block requires the workspace to belong to an organization' },
|
||||
{ status: 400 }
|
||||
)
|
||||
}
|
||||
const organizationId = ws.organizationId
|
||||
|
||||
if (!(await isFeatureEnabled('deploy-as-block', { userId, orgId: organizationId }))) {
|
||||
return NextResponse.json({ error: 'Deploy as block is not enabled' }, { status: 403 })
|
||||
|
||||
Reference in New Issue
Block a user