Prevent sharing a diagram with yourself
RLS is the real guard (diagram_collaborators_insert/update now reject user_id = the diagram's owner, regardless of who's performing the write — covers a Super Admin acting on someone else's diagram too, not just the normal owner path); the client-side check in SupabaseDiagramCollaboratorRepository.add is just there to surface a friendly message instead of the raw 42501. Verified: tsc -b and oxlint clean; supabase db reset + 53/53 pgTAP tests pass (1 new test).
This commit is contained in:
@@ -25,7 +25,7 @@ begin;
|
||||
|
||||
create extension if not exists pgtap with schema extensions;
|
||||
|
||||
select plan(52);
|
||||
select plan(53);
|
||||
|
||||
-- ----------------------------------------------------------------------
|
||||
-- Fixtures (as postgres — RLS does not apply)
|
||||
@@ -138,6 +138,13 @@ select throws_ok(
|
||||
|
||||
select set_config('request.jwt.claim.sub', '11111111-1111-1111-1111-111111111111', true);
|
||||
|
||||
select throws_ok(
|
||||
$$ insert into public.diagram_collaborators (diagram_id, user_id, permission)
|
||||
values ('b0000000-0000-0000-0000-000000000001', '11111111-1111-1111-1111-111111111111', 'edit') $$,
|
||||
'42501'::char(5), null,
|
||||
'alice (owner) cannot add herself as a collaborator on her own diagram'
|
||||
);
|
||||
|
||||
select lives_ok(
|
||||
$$ insert into public.diagram_collaborators (diagram_id, user_id, permission)
|
||||
values ('b0000000-0000-0000-0000-000000000001', '22222222-2222-2222-2222-222222222222', 'view') $$,
|
||||
|
||||
Reference in New Issue
Block a user