fix(file): verify target folder ownership on move

When moving a file to a folder, verify that the caller owns the target
folder. Without this check, a file could be moved to another user's
folder, causing the file to "disappear" from the original user's view
since file listings filter by user_id.

- Add folder_repo to FileManagementService
- Add verify_target_folder_owner() method
- Call it in move_file_owned() before moving
This commit is contained in:
BillionClaw
2026-03-17 16:53:55 +08:00
parent d1699357d8
commit 30d6e53fca
2 changed files with 40 additions and 1 deletions
+1
View File
@@ -261,6 +261,7 @@ impl AppServiceFactory {
repos.file_write_repository.clone(),
trash_service.clone(),
Some(repos.file_read_repository.clone()),
Some(repos.folder_repository.clone()),
Some(core.thumbnail_service.clone()),
));