feat(drive): check user grants on drive

use drive's grant whant handling a file or folder
This commit is contained in:
Edouard Vanbelle
2026-06-23 00:44:24 +02:00
parent 2fe9c9ffeb
commit 4eb9707774
4 changed files with 365 additions and 58 deletions
@@ -330,6 +330,20 @@ impl FileBlobReadRepository {
.ok_or_else(|| DomainError::not_found("File", file_id))
}
/// Returns `drive_id` for a given file. Drives the permission-floor
/// short-circuit in `PgAclEngine::check_inner` — drive membership is
/// the baseline floor per `drive.md §5`.
pub async fn get_file_drive_id(&self, file_id: &str) -> Result<uuid::Uuid, DomainError> {
sqlx::query_scalar::<_, uuid::Uuid>(
"SELECT drive_id FROM storage.files WHERE id = $1::uuid",
)
.bind(file_id)
.fetch_optional(self.pool.as_ref())
.await
.map_err(|e| DomainError::internal_error("FileBlobRead", format!("drive_id lookup: {e}")))?
.ok_or_else(|| DomainError::not_found("File", file_id))
}
/// Creates a stub instance for testing — never hits PG.
#[cfg(test)]
pub fn new_stub() -> Self {
@@ -1335,6 +1335,19 @@ impl FolderDbRepository {
.ok_or_else(|| DomainError::not_found("Folder", folder_id))
}
/// Returns `drive_id` for a given folder. Drives the new permission-floor
/// short-circuit in `PgAclEngine::check_inner` (a caller with any role
/// on the folder's drive automatically passes the check — drive
/// membership is the baseline floor per `drive.md §5`).
pub async fn get_folder_drive_id(&self, folder_id: &str) -> Result<Uuid, DomainError> {
sqlx::query_scalar::<_, Uuid>("SELECT drive_id FROM storage.folders WHERE id = $1::uuid")
.bind(folder_id)
.fetch_optional(self.pool())
.await
.map_err(|e| DomainError::internal_error("FolderDb", format!("drive_id lookup: {e}")))?
.ok_or_else(|| DomainError::not_found("Folder", folder_id))
}
/// Verifies that `folder_id` is owned by `owner_id`.
///
/// Returns `DomainError::not_found(...)` for both "folder missing" and