Prevent sharing a diagram with yourself
RLS is the real guard (diagram_collaborators_insert/update now reject user_id = the diagram's owner, regardless of who's performing the write — covers a Super Admin acting on someone else's diagram too, not just the normal owner path); the client-side check in SupabaseDiagramCollaboratorRepository.add is just there to surface a friendly message instead of the raw 42501. Verified: tsc -b and oxlint clean; supabase db reset + 53/53 pgTAP tests pass (1 new test).
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
import { useEffect, useState } from 'react'
|
||||
import type { CollaboratorPermission } from '../../data/DiagramCollaboratorRepository'
|
||||
import { UnknownUsernameError } from '../../data/DiagramCollaboratorRepository'
|
||||
import { SelfCollaboratorError, UnknownUsernameError } from '../../data/DiagramCollaboratorRepository'
|
||||
import { useDiagramCollaboratorStore } from '../../state/diagramCollaboratorStore'
|
||||
import { useProjectStore } from '../../state/projectStore'
|
||||
import Modal from '../common/Modal'
|
||||
@@ -36,7 +36,11 @@ export default function DiagramSharingModal({ onClose }: { onClose: () => void }
|
||||
await add(diagramId, trimmed, permission)
|
||||
setUsername('')
|
||||
} catch (err) {
|
||||
setError(err instanceof UnknownUsernameError ? err.message : 'Could not add that person. Try again.')
|
||||
setError(
|
||||
err instanceof UnknownUsernameError || err instanceof SelfCollaboratorError
|
||||
? err.message
|
||||
: 'Could not add that person. Try again.',
|
||||
)
|
||||
} finally {
|
||||
setBusy(false)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user