summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKyren223 <Kyren223@proton.me>2025-02-04 19:08:22 +0200
committerKyren223 <Kyren223@proton.me>2025-02-04 19:08:22 +0200
commitd9ae3018180e12c8b79361ef58c9e9e7114d80aa (patch)
treef96e3865aa95287e19dfa48285100a0ad4c4aa91
parenteab8cba4bb37491d5c3b497b98faa7029e7b7300 (diff)
Reverted back the removal of the logic in get notifications to check if
the user has access to the frequency, because it is needed for the is_admin ping type but also to prevent the case where someone was an admin, got demoted and can now monitor when new messages are sent there
-rw-r--r--internal/server/api/helpers.go13
1 files changed, 12 insertions, 1 deletions
diff --git a/internal/server/api/helpers.go b/internal/server/api/helpers.go
index c4deb6c..27c6f55 100644
--- a/internal/server/api/helpers.go
+++ b/internal/server/api/helpers.go
@@ -132,10 +132,20 @@ func UserPropagate(
}
const getNotificationsQuery = `-- name: GetNotifications :many
-WITH entries AS (
+WITH
+entries AS (
SELECT source_id, last_read
FROM last_read_messages
WHERE user_id = ?
+),
+permitted_frequencies AS (
+ SELECT f.id, m.is_admin
+ FROM frequencies f
+ JOIN entries e ON f.id = e.source_id
+ LEFT JOIN members m
+ ON m.user_id = ?
+ AND m.network_id = f.network_id
+ WHERE m.is_member = true AND (f.perms != 0 OR m.is_admin = true)
)
SELECT
e.source_id,
@@ -149,6 +159,7 @@ LEFT JOIN messages m ON m.id > e.last_read
AND (m.frequency_id = e.source_id OR
(m.receiver_id = e.source_id AND m.sender_id = ?) OR
(m.sender_id = e.source_id AND m.receiver_id = ?))
+JOIN permitted_frequencies pf ON e.source_id = pf.id
GROUP BY e.source_id, e.last_read;
`