@ -665,16 +665,27 @@ impl Cipher {
}
}
async fn get_user_collections_access_flags ( & self , user_uuid : & UserId , conn : & DbConn ) -> Vec < ( bool , bool , bool ) > {
async fn get_user_collections_access_flags ( & self , user_uuid : & UserId , conn : & DbConn ) -> Vec < ( bool , bool , bool ) > {
let user_uuid = user_uuid . to_string ( ) ;
conn . run ( move | conn | {
conn . run ( move | conn | {
// Check whether this cipher is in any collections accessible to the
// Check whether this cipher is in any collections accessible to the
// user. If so, retrieve the access flags for each collection.
// user. If so, retrieve the access flags for each collection.
// The user must have a confirmed membership in the cipher's
// organization, since users_collections rows are kept when a
// membership is revoked or not confirmed yet.
ciphers ::table
ciphers ::table
. filter ( ciphers ::uuid . eq ( & self . uuid ) )
. filter ( ciphers ::uuid . eq ( & self . uuid ) )
. inner_join ( ciphers_collections ::table . on ( ciphers ::uuid . eq ( ciphers_collections ::cipher_uuid ) ) )
. inner_join ( ciphers_collections ::table . on ( ciphers ::uuid . eq ( ciphers_collections ::cipher_uuid ) ) )
. inner_join (
users_organizations ::table . on ( ciphers ::organization_uuid
. eq ( users_organizations ::org_uuid . nullable ( ) )
. and ( users_organizations ::user_uuid . eq ( user_uuid ) )
. and ( users_organizations ::status . eq ( MembershipStatus ::Confirmed as i32 ) ) ) ,
)
. inner_join (
. inner_join (
users_collections ::table . on ( ciphers_collections ::collection_uuid
users_collections ::table . on ( ciphers_collections ::collection_uuid
. eq ( users_collections ::collection_uuid )
. eq ( users_collections ::collection_uuid )
. and ( users_collections ::user_uuid . eq ( user_uuid ) ) ) ,
// Only allow collection access via the confirmed membership.
. and ( users_organizations ::user_uuid . eq ( users_collections ::user_uuid ) ) ) ,
)
)
. select ( ( users_collections ::read_only , users_collections ::hide_passwords , users_collections ::manage ) )
. select ( ( users_collections ::read_only , users_collections ::hide_passwords , users_collections ::manage ) )
. load ::< ( bool , bool , bool ) > ( conn )
. load ::< ( bool , bool , bool ) > ( conn )
@ -705,6 +716,9 @@ impl Cipher {
. and ( groups ::organizations_uuid . eq ( users_organizations ::org_uuid ) ) ) ,
. and ( groups ::organizations_uuid . eq ( users_organizations ::org_uuid ) ) ) ,
)
)
. filter ( users_organizations ::user_uuid . eq ( user_uuid ) )
. filter ( users_organizations ::user_uuid . eq ( user_uuid ) )
// Only allow group access via a confirmed membership, since
// groups_users rows are kept when a membership is revoked.
. filter ( users_organizations ::status . eq ( MembershipStatus ::Confirmed as i32 ) )
. select ( ( collections_groups ::read_only , collections_groups ::hide_passwords , collections_groups ::manage ) )
. select ( ( collections_groups ::read_only , collections_groups ::hide_passwords , collections_groups ::manage ) )
. load ::< ( bool , bool , bool ) > ( conn )
. load ::< ( bool , bool , bool ) > ( conn )
. expect ( "Error getting group access restrictions" )
. expect ( "Error getting group access restrictions" )