From 79fda7b8c21477fa9dfa641497a632afe5accb93 Mon Sep 17 00:00:00 2001 From: KernelDeimos <7225168+KernelDeimos@users.noreply.github.com> Date: Tue, 20 Jan 2026 12:10:30 -0500 Subject: [PATCH] fix(backend): update protected app perm implicator The permission implicator for protected apps was written before changes to the permission system that affect the conditions under which a user is allowed to grant and revoke permissions; specifically this is the `manage:` set of permissions, which now needs to be granted to the owner of a protected app. Additionally, the "level" component of the permission is ignored because the owner of a protected all is implied to have all the permissions pertaining to that protected app. --- src/backend/src/modules/apps/ProtectedAppService.js | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/src/backend/src/modules/apps/ProtectedAppService.js b/src/backend/src/modules/apps/ProtectedAppService.js index 7b1764435..5adc302b1 100644 --- a/src/backend/src/modules/apps/ProtectedAppService.js +++ b/src/backend/src/modules/apps/ProtectedAppService.js @@ -59,7 +59,7 @@ class ProtectedAppService extends BaseService { // Owner of procted app has implicit permission to access it svc_permission.register_implicator(PermissionImplicator.create({ matcher: permission => { - return permission.startsWith('app:'); + return permission.startsWith('app:') || permission.startsWith('manage:app'); }, checker: async ({ actor, permission }) => { if ( ! (actor.type instanceof UserActorType) ) { @@ -67,10 +67,12 @@ class ProtectedAppService extends BaseService { } const parts = PermissionUtil.split(permission); - if ( parts.length !== 3 ) return undefined; - const [_, uid_part, lvl] = parts; - if ( lvl !== 'access' ) return undefined; + if ( parts[0] === 'manage' ) parts.shift(); + + if ( parts.length < 2 ) return undefined; + + const [_, uid_part] = parts; // track: slice a prefix const uid = uid_part.slice('uid#'.length);