fix(file): verify target folder ownership on move
When moving a file to a folder, verify that the caller owns the target folder. Without this check, a file could be moved to another user's folder, causing the file to "disappear" from the original user's view since file listings filter by user_id. - Add folder_repo to FileManagementService - Add verify_target_folder_owner() method - Call it in move_file_owned() before moving
This commit is contained in:
@@ -261,6 +261,7 @@ impl AppServiceFactory {
|
||||
repos.file_write_repository.clone(),
|
||||
trash_service.clone(),
|
||||
Some(repos.file_read_repository.clone()),
|
||||
Some(repos.folder_repository.clone()),
|
||||
Some(core.thumbnail_service.clone()),
|
||||
));
|
||||
|
||||
|
||||
Reference in New Issue
Block a user