Skip to content

Add per-user ownership check to dashboard load/update/delete - #1378

Merged
xuwei-fit2cloud merged 1 commit into
dataease:mainfrom
carfeii:fix/dashboard-ownership-check
Sep 17, 2026
Merged

xuwei-fit2cloud merged 1 commit into
dataease:mainfrom
carfeii:fix/dashboard-ownership-check

Conversation

@carfeii

@carfeii carfeii commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Fixes #1377

Adds a per-user ownership check (create_by vs. the caller's own id) to load_resource, update_resource, update_canvas, and delete_resource in apps/dashboard/crud/dashboard_service.py, matching the check list_resource already applies when listing dashboards. Previously these four functions fetched a core_dashboard row by id alone, and the only gating decorator (require_permissions(type='dashboard', ...)) only verified workspace membership rather than per-user ownership, allowing any authenticated member of a workspace to read, rename, or delete any other member's dashboard.

load_resource_api now passes current_user through to load_resource so the ownership check has the caller's identity available.

Dashboard resource endpoints (load_resource, update_resource,
update_canvas, delete_resource) fetched a core_dashboard row by id
alone, with no check that the caller created it. The only gating
decorator verified workspace membership, not per-user ownership, so
any authenticated workspace member could read, rename, or delete any
other member's dashboard by id. list_resource already filters by
create_by, showing dashboards are meant to be private per creator;
this adds the same check to the other four code paths.
@xuwei-fit2cloud
xuwei-fit2cloud merged commit fccdd29 into dataease:main Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants