feat(authz): check permission on read handlers + check create permission on folder

This commit is contained in:
Edouard Vanbelle
2026-05-21 11:07:04 +02:00
parent cba9be8c21
commit 3362e277ab
21 changed files with 428 additions and 180 deletions
+10 -5
View File
@@ -38,6 +38,7 @@ use crate::infrastructure::services::file_content_cache::{
use crate::infrastructure::services::file_system_i18n_service::FileSystemI18nService;
use crate::infrastructure::services::nextcloud_chunked_upload_service::NextcloudChunkedUploadService;
use crate::infrastructure::services::path_service::PathService;
use crate::infrastructure::services::pg_acl_engine::PgAclEngine;
use crate::infrastructure::services::trash_cleanup_service::TrashCleanupService;
use crate::application::services::app_password_service::AppPasswordService;
@@ -350,7 +351,7 @@ impl AppServiceFactory {
repos: &RepositoryServices,
trash_service: Option<Arc<TrashService>>,
db_pool: &Arc<PgPool>,
authz: &Arc<crate::infrastructure::services::pg_acl_engine::PgAclEngine>,
authz: &Arc<PgAclEngine>,
) -> ApplicationServices {
// Main services
let folder_service = Arc::new(FolderService::new(
@@ -452,6 +453,7 @@ impl AppServiceFactory {
&self,
repos: &RepositoryServices,
core: &CoreServices,
authz: &Arc<PgAclEngine>,
) -> Option<Arc<TrashService>> {
if !self.config.features.enable_trash {
tracing::info!("Trash service is disabled in configuration");
@@ -470,6 +472,7 @@ impl AppServiceFactory {
core.dedup_service.clone(),
Some(core.thumbnail_service.clone()),
Some(core.file_content_cache.clone()),
authz.clone(),
));
// Initialize cleanup service (bulk-deletes expired items in 2 SQL queries)
@@ -609,10 +612,7 @@ impl AppServiceFactory {
// 2. Repository services (requires PgPool for all metadata)
let repos = self.create_repository_services(&core, &pool);
// 3. Trash service (needed before application services)
let trash_service = self.create_trash_service(&repos, &core).await;
// 3b. Authorization engine — must exist before application services
// 3a. Authorization engine — must exist before application services
// because services hold an Arc<PgAclEngine> for ReBAC checks.
let authorization = build_authorization_engine(
pool.clone(),
@@ -620,6 +620,11 @@ impl AppServiceFactory {
repos.file_read_repository.clone(),
);
// 3b. Trash service (needed before application services)
let trash_service = self
.create_trash_service(&repos, &core, &authorization)
.await;
// 4. Application services (with trash + authz already wired)
let mut apps = self.create_application_services(
&core,
+30 -7
View File
@@ -34,6 +34,7 @@ use crate::common::errors::DomainError;
use crate::domain::entities::file::File;
use crate::domain::entities::folder::Folder;
use crate::domain::repositories::folder_repository::FolderRepository;
use crate::domain::services::authorization::Permission;
use crate::domain::services::i18n_service::{I18nResult, I18nService, Locale};
use crate::domain::services::path_service::StoragePath;
@@ -355,6 +356,15 @@ impl I18nService for StubI18nService {
pub struct StubFolderUseCase;
impl FolderUseCase for StubFolderUseCase {
async fn has_permission(
&self,
_caller_id: Uuid,
_permission: Permission,
_file_id: &str,
) -> Result<(), DomainError> {
Ok(())
}
async fn create_folder_with_perms(
&self,
_dto: CreateFolderDto,
@@ -383,7 +393,7 @@ impl FolderUseCase for StubFolderUseCase {
Ok(Vec::new())
}
async fn list_folders_for_owner(
async fn list_folders_with_perms(
&self,
_parent_id: Option<&str>,
_owner_id: Uuid,
@@ -399,7 +409,7 @@ impl FolderUseCase for StubFolderUseCase {
Ok(PaginatedResponseDto::new(Vec::new(), 0, 10, 0))
}
async fn list_folders_for_owner_paginated(
async fn list_folders_paginated_with_perms(
&self,
_parent_id: Option<&str>,
_owner_id: Uuid,
@@ -521,7 +531,7 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
Ok(Vec::new())
}
async fn list_files_owned(
async fn list_files_with_perms(
&self,
_folder_id: Option<&str>,
_owner_id: Uuid,
@@ -537,7 +547,7 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
Ok(Box::new(empty_stream))
}
async fn get_file_stream_owned(
async fn get_file_stream_with_perms(
&self,
_id: &str,
_caller_id: Uuid,
@@ -583,11 +593,15 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
Ok(Box::pin(futures::stream::empty()))
}
async fn get_file_owned(&self, _id: &str, _caller_id: Uuid) -> Result<FileDto, DomainError> {
async fn get_file_with_perms(
&self,
_id: &str,
_caller_id: Uuid,
) -> Result<FileDto, DomainError> {
Ok(FileDto::default())
}
async fn get_file_optimized_owned(
async fn get_file_optimized_with_perms(
&self,
_id: &str,
_caller_id: Uuid,
@@ -604,7 +618,7 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
))
}
async fn get_file_range_stream_owned(
async fn get_file_range_stream_with_perms(
&self,
_id: &str,
_caller_id: Uuid,
@@ -623,6 +637,15 @@ impl FileRetrievalUseCase for StubFileRetrievalUseCase {
pub struct StubFileManagementUseCase;
impl FileManagementUseCase for StubFileManagementUseCase {
async fn has_permission(
&self,
_caller_id: Uuid,
_permission: Permission,
_file_id: &str,
) -> Result<(), DomainError> {
Ok(())
}
async fn copy_file_with_perms(
&self,
_file_id: &str,