feat(drive): repl user_id by caller has read access

repl user_id by caller has read access in readonly functions
    using CALLER_CAN_READ_DRIVE constant

    ensure webdav preview is using the permission handler
This commit is contained in:
Edouard Vanbelle
2026-07-02 00:45:11 +02:00
parent 79bc60899b
commit 09790644f3
9 changed files with 249 additions and 148 deletions
+16 -16
View File
@@ -431,23 +431,23 @@ impl FolderUseCase for FolderService {
return self.list_folders_paginated(parent_id, &pagination).await;
} else {
let (folders, total_items) = self
.folder_storage
.list_root_folders_for_caller_paginated(
owner_id,
pagination.offset(),
pagination.limit(),
true,
)
.await
.map_err(|e| {
DomainError::internal_error(
"FolderStorage",
format!(
"Failed to list root folders for caller '{}' with pagination: {}",
owner_id, e
),
.folder_storage
.list_root_folders_for_caller_paginated(
owner_id,
pagination.offset(),
pagination.limit(),
true,
)
})?;
.await
.map_err(|e| {
DomainError::internal_error(
"FolderStorage",
format!(
"Failed to list root folders for caller '{}' with pagination: {}",
owner_id, e
),
)
})?;
let total = total_items.unwrap_or(folders.len());
+4 -3
View File
@@ -9,9 +9,10 @@ use crate::infrastructure::repositories::pg::FileBlobReadRepository;
/// "Places" use case: the caller's geotagged photos aggregated into map
/// clusters.
///
/// Post-§15 the surface follows the Photos scope: default personal drive
/// + drives where `policies.include_in_photo_index = true` AND caller
/// has Read. Group-membership expansion is handled inline by
/// Post-§15 the surface follows the Photos scope: drives where the
/// caller has Read AND `policies.include_in_photo_index = true`
/// (default personal drives materialise the flag at creation).
/// Group-membership expansion is handled inline by
/// `storage.caller_group_ids(caller)` inside the repo's SQL, so this
/// service is a thin coordinate-math wrapper — no engine dependency.
pub struct PlacesService {
+5 -1
View File
@@ -328,7 +328,11 @@ impl SearchService {
}
};
match authz
.check(Subject::User(user_id), Permission::Read, Resource::File(file_uuid))
.check(
Subject::User(user_id),
Permission::Read,
Resource::File(file_uuid),
)
.await
{
Ok(true) => verified.push(hit),