Skip to content

Commit 7982803

Browse files
Fix person invite (#11051)
Signed-off-by: Artyom Savchenko <armisav@gmail.com>
1 parent 90d418c commit 7982803

2 files changed

Lines changed: 31 additions & 2 deletions

File tree

‎foundations/server/packages/middleware/src/guestPermissions.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -207,7 +207,7 @@ export class GuestPermissionsMiddleware extends BaseMiddleware implements Middle
207207
(tx as TxMixin<Doc, Doc>).mixin === contact.mixin.Employee &&
208208
!h.hasMixin(person, contact.mixin.Employee)
209209
) {
210-
return true
210+
return person.personUuid !== account.uuid
211211
}
212212
return !this.canUserEditPersonContactDetails(person, account)
213213
}

‎foundations/server/packages/middleware/src/tests/guestPermissions.test.ts‎

Lines changed: 30 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -378,7 +378,36 @@ describe('GuestPermissionsMiddleware', () => {
378378
await expect(mw.tx(makeCtx(account), [tx])).rejects.toThrow()
379379
})
380380

381-
it('forbids a user from adding the employee mixin to a person', async () => {
381+
it('allows a user to add the employee mixin to their own person', async () => {
382+
const personId = generateId()
383+
const account = makeAccount(AccountRole.User)
384+
let nextCalled = false
385+
const findAll: FindAllFn = async (_ctx, _class, query: any) => {
386+
if (_class === contact.class.Person && query?._id === personId) {
387+
return [makePersonDoc(personId, account.uuid, false)]
388+
}
389+
return []
390+
}
391+
const mw = makeMiddleware(findAll, async () => {
392+
nextCalled = true
393+
return {}
394+
})
395+
patchContactHierarchy(mw)
396+
397+
const factory = new TxFactory(account.primarySocialId)
398+
const tx = factory.createTxMixin(
399+
personId,
400+
contact.class.Person as Ref<Class<Doc>>,
401+
'contact:space:Contacts' as Ref<Space>,
402+
contact.mixin.Employee,
403+
{ active: true } as any
404+
)
405+
406+
await mw.tx(makeCtx(account), [tx])
407+
expect(nextCalled).toBe(true)
408+
})
409+
410+
it('forbids a user from adding the employee mixin to another person', async () => {
382411
const personId = generateId()
383412
const account = makeAccount(AccountRole.User)
384413
const findAll: FindAllFn = async (_ctx, _class, query: any) => {

0 commit comments

Comments
 (0)