feat: tenant isolation Phase 0 — app-layer filters, UUID audit, CI gate #132
@@ -72,8 +72,8 @@ async def create_share(
|
|||||||
|
|
||||||
if session.user_id != current_user.id and not current_user.is_super_admin:
|
if session.user_id != current_user.id and not current_user.is_super_admin:
|
||||||
raise HTTPException(
|
raise HTTPException(
|
||||||
status_code=status.HTTP_403_FORBIDDEN,
|
status_code=status.HTTP_404_NOT_FOUND,
|
||||||
detail="Only the session owner can create share links"
|
detail="Session not found"
|
||||||
)
|
)
|
||||||
|
|
||||||
# Require account_id for account-scoped shares
|
# Require account_id for account-scoped shares
|
||||||
@@ -170,8 +170,8 @@ async def revoke_share(
|
|||||||
|
|
||||||
if share.created_by != current_user.id and not current_user.is_super_admin:
|
if share.created_by != current_user.id and not current_user.is_super_admin:
|
||||||
raise HTTPException(
|
raise HTTPException(
|
||||||
status_code=status.HTTP_403_FORBIDDEN,
|
status_code=status.HTTP_404_NOT_FOUND,
|
||||||
detail="Only the share creator can revoke it"
|
detail="Share not found"
|
||||||
)
|
)
|
||||||
|
|
||||||
share.is_active = False
|
share.is_active = False
|
||||||
|
|||||||
Reference in New Issue
Block a user