From c7bbf6a987a6e5cd39b9e29bf59e7c88197d0afd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Matej=20Ba=C4=8Do?= Date: Mon, 16 Feb 2026 16:14:43 +0100 Subject: [PATCH] fix org keys auth --- app/controllers/shared/api.php | 10 ++++++++-- app/init/resources.php | 3 +++ 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/app/controllers/shared/api.php b/app/controllers/shared/api.php index 378c5d5c9c..7e4cff32f4 100644 --- a/app/controllers/shared/api.php +++ b/app/controllers/shared/api.php @@ -169,8 +169,10 @@ Http::init() // Handle special app role case if ($apiKey->getRole() === User::ROLE_APPS) { - // Disable authorization checks for API keys - $authorization->setDefaultStatus(false); + // Disable authorization checks for project API keys + if ($project->getId() !== 'console') { + $authorization->setDefaultStatus(false); + } $user = new User([ '$id' => '', @@ -245,6 +247,10 @@ Http::init() } } + $authorization->addRole(Role::team($team->getId())->toString()); + $authorization->addRole(Role::team($team->getId(), 'owner')->toString()); + $authorization->addRole(Role::member($team->getId())->toString()); + $queueForAudits->setUser($user); } } // Admin User Authentication diff --git a/app/init/resources.php b/app/init/resources.php index cdc2e8a367..b2a7a0189d 100644 --- a/app/init/resources.php +++ b/app/init/resources.php @@ -1304,6 +1304,7 @@ Http::setResource('team', function (Document $project, Database $dbForPlatform, } else { $route = $utopia->match($request); $path = !empty($route) ? $route->getPath() : $request->getURI(); + $orgHeader = $request->getHeader('x-appwrite-organization', ''); if (str_starts_with($path, '/v1/projects/:projectId')) { $uri = $request->getURI(); $pid = explode('/', $uri)[3]; @@ -1318,6 +1319,8 @@ Http::setResource('team', function (Document $project, Database $dbForPlatform, $team = $authorization->skip(fn () => $dbForPlatform->getDocument('teams', $teamId)); return $team; + } elseif (!empty($orgHeader)) { + return $authorization->skip(fn () => $dbForPlatform->getDocument('teams', $orgHeader)); } }