Changeset 0.24.3 (#159)
This commit is contained in:
@@ -87,7 +87,13 @@ func (h *MessageHandler) ListMessages(c *gin.Context) {
|
||||
userID := getUserID(c)
|
||||
channelID := c.Param("id")
|
||||
|
||||
if !userOwnsChannel(c, channelID, userID) {
|
||||
// v0.24.3: Session participants are pre-validated by AuthOrSession middleware
|
||||
if isSessionAuth(c) {
|
||||
if !sessionCanAccessChannel(c, channelID) {
|
||||
c.JSON(http.StatusForbidden, gin.H{"error": "session not authorized for this channel"})
|
||||
return
|
||||
}
|
||||
} else if !userOwnsChannel(c, channelID, userID) {
|
||||
return
|
||||
}
|
||||
|
||||
@@ -193,16 +199,31 @@ func (h *MessageHandler) CreateMessage(c *gin.Context) {
|
||||
userID := getUserID(c)
|
||||
channelID := c.Param("id")
|
||||
|
||||
if !userOwnsChannel(c, channelID, userID) {
|
||||
// v0.24.3: Session participants are pre-validated by AuthOrSession middleware
|
||||
if isSessionAuth(c) {
|
||||
if !sessionCanAccessChannel(c, channelID) {
|
||||
c.JSON(http.StatusForbidden, gin.H{"error": "session not authorized for this channel"})
|
||||
return
|
||||
}
|
||||
} else if !userOwnsChannel(c, channelID, userID) {
|
||||
return
|
||||
}
|
||||
|
||||
// Use cursor for parent, compute sibling_index
|
||||
parentID, _ := getActiveLeaf(channelID, userID)
|
||||
// Sessions use the same cursor logic (empty userID = channel-level latest)
|
||||
effectiveUserID := userID
|
||||
if isSessionAuth(c) {
|
||||
effectiveUserID = c.GetString("session_id")
|
||||
}
|
||||
parentID, _ := getActiveLeaf(channelID, effectiveUserID)
|
||||
siblingIdx := nextSiblingIndex(channelID, parentID)
|
||||
|
||||
participantType := "user"
|
||||
participantID := userID
|
||||
if isSessionAuth(c) {
|
||||
participantType = "session"
|
||||
participantID = c.GetString("session_id")
|
||||
}
|
||||
if req.Role == "assistant" {
|
||||
participantType = "model"
|
||||
if req.Model != "" {
|
||||
|
||||
Reference in New Issue
Block a user