refactor(create_folder): add an ownership check while creating a folder + refactor code

This commit is contained in:
Edouard Vanbelle
2026-05-20 12:48:06 +02:00
parent 91ff3df35f
commit f8b30e78a6
9 changed files with 76 additions and 89 deletions
@@ -1044,4 +1044,20 @@ impl FolderDbRepository {
.map_err(|e| DomainError::internal_error("FolderDb", format!("user_id lookup: {e}")))?
.ok_or_else(|| DomainError::not_found("Folder", folder_id))
}
/// Verifies that `folder_id` is owned by `owner_id`.
///
/// Returns `DomainError::not_found(...)` for both "folder missing" and
/// "folder owned by someone else" — same error to avoid leaking the
/// existence of resources belonging to other users.
pub async fn verify_owner(&self, folder_id: &str, owner_id: Uuid) -> Result<(), DomainError> {
let actual = self.get_folder_user_id(folder_id).await?;
if actual != owner_id {
return Err(DomainError::not_found(
"Folder",
"Target folder not found or access denied",
));
}
Ok(())
}
}