4abda62a99 fix(labels): allow attaching labels via inherited child-project access (#3374)
Users with access to parent project could remove labels from tasks in
child projects but not add them back — 403 "Tried to create while not
having the permissions for it". Label attach check used direct shares
only; task write permission and label picker both walk project
hierarchy. Fix: label access now uses same recursive subquery.

Reported: https://community.vikunja.io/t/permissions-on-labels/4460

## How to verify

1. As user A, create a parent project with a child project, and add a
task in the child project.
2. Share the parent project with a team that has write access and
contains user B.
3. As user A, add a label to the task in the child project.
4. As user B, open that task, remove the label, then try to add it back.
5. **Expected:** the label can be added again; the API returns 201.

**Before this PR:** step 4 failed with 403 even though user B could edit
the task and remove the label.

Co-authored-by: kolaente <k@knt.li>
2026-07-30 12:03:30 +02:00
2026-07-19 12:58:41 +02:00
2026-07-27 09:29:16 +00:00

Build Status License: AGPL-3.0-or-later Install Docker Pulls OpenAPI Docs

Vikunja

The task manager you actually own.

If Vikunja is useful to you, please consider supporting the project. You can buy a coffee, sponsor on GitHub or buy a sticker pack. We're also offering a hosted version of Vikunja if you want a hassle-free solution for yourself or your team. If you or your company needs admin panel, audit logs or time tracking, check out Vikunja Pro.

Note

For the development of Vikunja, we're using LLM-Assisted coding tools in various parts of the codebase. Most contributions made @tink-bot are built that way.

Table of contents

Security Reports

If you find any security-related issues you don't want to disclose publicly, please use the contact information on our website.

Features

See the features page on our website for a more exhaustive list or try it on try.vikunja.io!

Docs

All docs can be found on the Vikunja home page.

Roadmap

See the roadmap (hosted on Vikunja!) for more!

Contributing

Please check out the contribution guidelines on the website.

License

Most of this repository is licensed under AGPL3.0orlater. The contents of desktop/ are licensed under GPL3.0orlater.

Unsplash Images

Background images from Unsplash are distributed under the Unsplash License. The license requires giving credit to the photographer and Unsplash. See Unsplashs terms for more information.

S
Description
No description provided
Readme AGPL-3.0
1.3 GiB
Latest
2026-08-04 06:42:44 -05:00
Languages
Go 50.1%
JavaScript 30.9%
TypeScript 9.7%
Vue 8.5%
SCSS 0.4%
Other 0.2%