feat(drive): remove _for_owner() and use authz

remove related IDOR protection as Hurl tests are covering this surface
This commit is contained in:
Edouard Vanbelle
2026-07-02 01:06:50 +02:00
parent 09790644f3
commit f5f5b1167f
9 changed files with 21 additions and 703 deletions
@@ -346,9 +346,8 @@ impl FileRetrievalUseCase for FileRetrievalService {
// Files always have a `folder_id` in the D0+ model — there is no
// longer any concept of "root-level files". A `None` from the
// caller means the query string was missing `folder_id`; reject
// with a clear error instead of routing through the legacy
// `list_files_for_owner` fallback (which used the doomed
// `user_id` column and returned empty in practice anyway).
// with a clear error rather than returning an empty set from a
// meaningless root-level query.
if folder_id.is_none() {
return Err(DomainError::validation_error("folder_id is required"));
}
@@ -469,20 +468,21 @@ impl FileRetrievalUseCase for FileRetrievalService {
offset: i64,
limit: i64,
) -> Result<Vec<FileDto>, DomainError> {
if folder_id.is_some() {
// folder id is defined, check permissions
self.require_target_folder_perm(folder_id, Permission::Read, owner_id)
.await?;
let files = self
.file_read
.list_files_batch(folder_id, offset, limit)
.await?;
return Ok(files.into_iter().map(FileDto::from).collect());
}
// Post-D0: every file lives in a folder — `storage.files.folder_id`
// is NOT NULL. `folder_id = None` means the caller is asking for
// "root-level files", which by design return an empty set: the
// WebDAV synthetic root only lists drive-root folders as
// children. Skip the DB round-trip and the pre-D7 owner-fallback
// query (which used to hit `_for_owner` and would have driven
// the `files.user_id` filter this refactor is retiring).
let Some(_) = folder_id else {
return Ok(Vec::new());
};
self.require_target_folder_perm(folder_id, Permission::Read, owner_id)
.await?;
let files = self
.file_read
.list_files_batch_for_owner(folder_id, owner_id, offset, limit)
.list_files_batch(folder_id, offset, limit)
.await?;
Ok(files.into_iter().map(FileDto::from).collect())
}