Skip to content

Commit 347785a

Browse files
committed
Claude review - add back perm check on shadowed view
1 parent fa116d6 commit 347785a

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

‎query/src/org/labkey/query/controllers/QueryController.java‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2597,7 +2597,8 @@ protected JSONObject saveCustomView(Container container, QueryDefinition queryDe
25972597

25982598
// GitHub Issue #1440: check perm view's container
25992599
Container viewContainer = view != null ? view.getContainer() : null;
2600-
if (viewContainer != null && !viewContainer.equals(container) && !canEditView(view, viewContainer, getUser()))
2600+
boolean shadowsSharedView = owner != null && view != null && view.isShared();
2601+
if (viewContainer != null && !shadowsSharedView && !viewContainer.equals(container) && !canEditView(view, viewContainer, getUser()))
26012602
throw new UnauthorizedException();
26022603

26032604
// 11179: Allow editing the view if we're saving to session.
@@ -6151,10 +6152,9 @@ else if (getUser().isGuest())
61516152
{
61526153
throw new UnauthorizedException();
61536154
}
6154-
else
6155+
else if (!getContainer().hasPermission(getUser(), ReadPermission.class) || !canEditView(view, getContainer(), getUser()))
61556156
{
6156-
if (!canEditView(view, getContainer(), getUser()))
6157-
throw new UnauthorizedException();
6157+
throw new UnauthorizedException();
61586158
}
61596159

61606160
view.delete(getUser(), getViewContext().getRequest());

0 commit comments

Comments
 (0)