fix(security): IDOR protection for file operations
Adds ownership verification at repository, service, and handler layers for download, rename, move, and delete file operations. - Repository: get_file_for_owner() with AND user_id= SQL filter - Service: _owned() methods with verify_owner() fail-closed guard - Handlers: require AuthUser, delegate to _owned() methods - Tests: 10 IDOR protection tests (all passing) - Cleanup: remove dead OptionalUserId import, gate broken pre-existing test modules behind integration_tests feature flag
This commit is contained in:
@@ -254,6 +254,7 @@ impl AppServiceFactory {
|
||||
let file_management_service = Arc::new(FileManagementService::with_trash(
|
||||
repos.file_write_repository.clone(),
|
||||
trash_service.clone(),
|
||||
Some(repos.file_read_repository.clone()),
|
||||
));
|
||||
|
||||
let file_use_case_factory = Arc::new(AppFileUseCaseFactory::new(
|
||||
|
||||
Reference in New Issue
Block a user