Prevent sharing a diagram with yourself

RLS is the real guard (diagram_collaborators_insert/update now reject
user_id = the diagram's owner, regardless of who's performing the write —
covers a Super Admin acting on someone else's diagram too, not just the
normal owner path); the client-side check in
SupabaseDiagramCollaboratorRepository.add is just there to surface a
friendly message instead of the raw 42501.

Verified: tsc -b and oxlint clean; supabase db reset + 53/53 pgTAP tests
pass (1 new test).
This commit is contained in:
2026-09-11 11:42:07 -05:00
parent dea26f7ee8
commit 4b757e89f5
5 changed files with 55 additions and 4 deletions
@@ -1,6 +1,6 @@
import { useEffect, useState } from 'react'
import type { CollaboratorPermission } from '../../data/DiagramCollaboratorRepository'
import { UnknownUsernameError } from '../../data/DiagramCollaboratorRepository'
import { SelfCollaboratorError, UnknownUsernameError } from '../../data/DiagramCollaboratorRepository'
import { useDiagramCollaboratorStore } from '../../state/diagramCollaboratorStore'
import { useProjectStore } from '../../state/projectStore'
import Modal from '../common/Modal'
@@ -36,7 +36,11 @@ export default function DiagramSharingModal({ onClose }: { onClose: () => void }
await add(diagramId, trimmed, permission)
setUsername('')
} catch (err) {
setError(err instanceof UnknownUsernameError ? err.message : 'Could not add that person. Try again.')
setError(
err instanceof UnknownUsernameError || err instanceof SelfCollaboratorError
? err.message
: 'Could not add that person. Try again.',
)
} finally {
setBusy(false)
}