mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-03-12 01:45:56 -05:00
[PR #1219] [MERGED] Ensure that a user is actually in an org when applying policies #2780
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/dani-garcia/vaultwarden/pull/1219
Author: @aveao
Created: 11/7/2020
Status: ✅ Merged
Merged: 11/7/2020
Merged by: @dani-garcia
Base:
master← Head:master📝 Commits (1)
fa364c3Ensure that a user is actually in an org when applying policies📊 Changes
1 file changed (+4 additions, -1 deletions)
View changed files
📝
src/db/models/org_policy.rs(+4 -1)📄 Description
While this patch (which is based on src/db/models/collection.rs's find_by_user_uuid) was initially to fix #1218, you already pushed
013d4c28b2just as I was making the PR.There's however one case that doesn't seem to account that is fixed by this PR: User B (owner of Org A) can invite User A to Org A, and even if User A doesn't accept this invitation, the policies will be applied to them:
I've tested this behavior with and without this patch, verified that that behavior happens, and that this PR resolves that issue.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.