fix: Check owner can create boards when importing#7341
Merged
juliusknorr merged 1 commit intomainfrom Nov 5, 2025
Merged
Conversation
Contributor
|
🐢 Performance warning. |
5e7ba3a to
780e843
Compare
Member
|
Just to double check, do we already hide the import functionality in the ui then? |
Contributor
Author
@juliusknorr Yes, the |
Signed-off-by: Luka Trovic <[email protected]>
780e843 to
8d4465b
Compare
juliusknorr
approved these changes
Nov 5, 2025
Contributor
Author
|
/backport to stable31 |
Contributor
Author
|
/backport to stable32 |
This was referenced Nov 6, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds permission checks to board import functionality to ensure that only users with the appropriate rights can create boards. The main changes involve enforcing these checks in both the UI controller and API controller, and extending unit tests to cover permission scenarios.
Permission enforcement improvements:
BoardController::importto throwNoPermissionExceptionif the user is not allowed to create boards.BoardImportApiController::import, preventing board creation via API for unauthorized users.Dependency and test updates:
PermissionServiceintoBoardImportApiControllerand updated its constructor accordingly.BoardImportApiControllerTestto mockPermissionService, test successful import when permitted, and add a new test for denied permission, ensuringNoPermissionExceptionis thrown.Checklist