0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-07 13:19:19 +08:00
discourse/plugins/discourse-calendar
Chris Alberti 6e5418453b
SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.1] (#42229)
Backport of #42187 to release/2026.1.

Manual backport required since livestream wasn't yet moved into
discourse-calendar at this time so related changes were removed, and a
couple other fixes were (cleanly) cherry-picked to support the backport:
- #37662 and #37663 
   InviteesController bug fixes
- #38023 
Moves InivteesController logic into Services and adds additional
security checks as policies
- #40487 
Stops memoizing can_act_on_discourse_post_event? so we don't fall back
to a cached value

---

## Summary

Correctly restrict private calendar event access to current group
members. The patch replaces stale invitee-row authorization with active
invited-group membership checks across event detail serialization,
attendance searches, RSVP mutations, and livestream chat metadata, and
prunes stale invitee records when a user is removed from a group.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1377

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>

---------

Co-authored-by: Joffrey JAFFEUX <j.jaffeux@gmail.com>
Co-authored-by: Renato Atilio <renato@discourse.org>
2026-08-03 10:37:47 -05:00
..
app SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.1] (#42229) 2026-08-03 10:37:47 -05:00
assets UX: avoid event node view being dragged when not selected (#37069) 2026-01-12 19:42:54 -03:00
config I18N: Update translations (#37916) 2026-02-25 09:47:58 -05:00
db/migrate FIX: event not found after being edited to earlier date (#36481) 2025-12-08 17:41:46 +01:00
jobs FIX: skip topic bump when date is in the past (#36784) 2025-12-18 21:29:06 +01:00
lib SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.1] (#42229) 2026-08-03 10:37:47 -05:00
spec SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.1] (#42229) 2026-08-03 10:37:47 -05:00
test/javascripts FEATURE: inline event editor for the rich editor (#36675) 2026-01-12 09:48:53 -03:00
vendor/holidays DEV: add 2026 India holidays (#37059) 2026-01-13 14:08:31 +05:30
.prettierignore
package.json DEV: Overhaul typechecking configuration (#35794) 2025-11-12 12:54:34 +00:00
plugin.rb SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.1] (#42229) 2026-08-03 10:37:47 -05:00
README.md
tsconfig.json DEV: Overhaul typechecking configuration (#35794) 2025-11-12 12:54:34 +00:00

Discourse Calendar

Adds the ability to create a dynamic calendar in the first post of a topic.

Topic discussing the plugin itself can be found here: https://meta.discourse.org/t/discourse-calendar/97376

Customization

Events

  • discourse_post_event_event_will_start this DiscourseEvent will be triggered one hour before an event starts
  • discourse_post_event_event_started this DiscourseEvent will be triggered when an event starts
  • discourse_post_event_event_ended this DiscourseEvent will be triggered when an event ends

Custom Fields

Custom fields can be set in plugin settings. Once added a new form will appear on event UI. These custom fields are available when a plugin event is triggered.

Holidays

See an incorrect or missing holiday? Familiarize yourself with the holiday definition Syntax. Then make your updates in the vendor/holiday/definitions directory.

Generate updated holidays as follows.

cd vendor/holidays

# Generate holiday definitions
rake generate:definitions

Install the plugin and switch to the discourse root(not the plugin directory).

# Collect all holiday regions into assets/javascripts/lib/regions.js
bin/rails javascript:update_constants

Interactions with Other Plugins

You can use an element of this plugin with the Right Sidebar Blocks component. You'll want to ensure the desired route is enabled via the events calendar categories setting. In Right Sidebar Block's settings, the block name will be upcoming-events-list, and the params use this syntax, for example MMMM D, YYYY.