From 15f31237f414cabbd46cae0a360f1b8debbd85c7 Mon Sep 17 00:00:00 2001 From: Hemachandar Date: Thu, 29 Jan 2026 18:16:04 +0530 Subject: [PATCH] auth checks --- app/controllers/shared/api.php | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/app/controllers/shared/api.php b/app/controllers/shared/api.php index 5c052879bb..dbd410b8a1 100644 --- a/app/controllers/shared/api.php +++ b/app/controllers/shared/api.php @@ -272,6 +272,14 @@ App::init() $scopes = \array_merge($scopes, $roles[$role]['scopes']); $authorization->addRole($role); } + + // For projects resources, ensure admin user has access to the retrieved project(s). + if ($project->getId() === 'console' && str_starts_with($route->getPath(), '/v1/projects')) { + $authorization->setDefaultStatus(true); + } else { + // Otherwise, disable authorization checks. + $authorization->setDefaultStatus(false); + } } $scopes = \array_unique($scopes); @@ -281,6 +289,23 @@ App::init() $authorization->addRole($authRole); } + // Ensure admin user has access to the non-console project. + if ($project->getId() !== 'console' && $mode === APP_MODE_ADMIN) { + $action = match ($route->getMethod()) { + Request::METHOD_GET => Database::PERMISSION_READ, + Request::METHOD_DELETE => Database::PERMISSION_DELETE, + default => Database::PERMISSION_UPDATE, + }; + $input = new Input($action, $project->getPermissionsByType($action)); + + $initialStatus = $authorization->getStatus(); + $authorization->enable(); + if (!$authorization->isValid($input)) { + throw new Exception(Exception::PROJECT_NOT_FOUND); + } + $authorization->setStatus($initialStatus); + } + // Step 6: Update project and user last activity if (!$project->isEmpty() && $project->getId() !== 'console') { $accessedAt = $project->getAttribute('accessedAt', 0);