0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-08 17:53:55 +08:00
discourse/plugins/discourse-calendar/app
Chris Alberti b786f5e1d3
SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.6] (#42219)
Backport of #42187 to release/2026.6.

---

## Summary

Correctly restrict private calendar event access to current group
members. The patch replaces stale invitee-row authorization with active
invited-group membership checks across event detail serialization,
attendance searches, RSVP mutations, and livestream chat metadata, and
prunes stale invitee records when a user is removed from a group.

## Source

- Patch Triage: https://patch.discourse.org/patch-triage/1377

Co-authored-by: discourse-patch-triage
<272280883+discourse-patch-triage[bot]@users.noreply.github.com>
2026-07-31 15:19:28 -05:00
..
controllers DEV: Extract mutating EventsController actions into services (#41053) 2026-06-24 18:45:06 -03:00
models SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.6] (#42219) 2026-07-31 15:19:28 -05:00
serializers SECURITY: Remove stale invitee access for users removed from invited groups on private events [backport 2026.6] (#42219) 2026-07-31 15:19:28 -05:00
services SECURITY: Private event invitee details leak through invitees list endpoint [backport 2026.6] (#42112) 2026-07-28 16:11:07 -05:00
views/discourse_post_event/events FIX: Treat all-day calendar events as date-only (#41203) 2026-06-29 11:30:38 +02:00