mirror of
https://github.com/discourse/discourse.git
synced 2026-08-07 13:19:19 +08:00
Backport of #42187 to release/2026.1. Manual backport required since livestream wasn't yet moved into discourse-calendar at this time so related changes were removed, and a couple other fixes were (cleanly) cherry-picked to support the backport: - #37662 and #37663 InviteesController bug fixes - #38023 Moves InivteesController logic into Services and adds additional security checks as policies - #40487 Stops memoizing can_act_on_discourse_post_event? so we don't fall back to a cached value --- ## Summary Correctly restrict private calendar event access to current group members. The patch replaces stale invitee-row authorization with active invited-group membership checks across event detail serialization, attendance searches, RSVP mutations, and livestream chat metadata, and prunes stale invitee records when a user is removed from a group. ## Source - Patch Triage: https://patch.discourse.org/patch-triage/1377 Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com> --------- Co-authored-by: Joffrey JAFFEUX <j.jaffeux@gmail.com> Co-authored-by: Renato Atilio <renato@discourse.org> |
||
|---|---|---|
| .. | ||
| discourse_calendar | ||
| discourse_post_event | ||
| tasks | ||
| calendar.rb | ||
| calendar_first_day_of_week.rb | ||
| calendar_settings_validator.rb | ||
| calendar_upcoming_events_default_view.rb | ||
| calendar_validator.rb | ||
| event_validator.rb | ||
| group_timezones.rb | ||
| holiday_status.rb | ||
| time_sniffer.rb | ||
| users_on_holiday.rb | ||